PT-2025-46142 · Qnap · Qnap Hbs 3+1
Published
2025-11-08
·
Updated
2026-03-30
·
CVE-2025-62840
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QNAP HBS 3 (Hybrid Backup Sync) versions prior to 26.2.0.938
Description
A flaw exists in QNAP HBS 3 (Hybrid Backup Sync) related to incorrect path restriction for an access-limited directory. Successful exploitation by a remote attacker could lead to unauthorized access to protected information. The issue involves the generation of error messages containing sensitive information. If an attacker gains local network access, they can exploit this to read application data.
Recommendations
Update to HBS 3 Hybrid Backup Sync version 26.2.0.938 or later.
Fix
Generation of Error Message Containing Sensitive Information
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hybrid Backup Sync
Qnap Hbs 3