PT-2025-46142 · Qnap · Qnap Hbs 3+1

Published

2025-11-08

·

Updated

2026-03-30

·

CVE-2025-62840

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions QNAP HBS 3 (Hybrid Backup Sync) versions prior to 26.2.0.938
Description A flaw exists in QNAP HBS 3 (Hybrid Backup Sync) related to incorrect path restriction for an access-limited directory. Successful exploitation by a remote attacker could lead to unauthorized access to protected information. The issue involves the generation of error messages containing sensitive information. If an attacker gains local network access, they can exploit this to read application data.
Recommendations Update to HBS 3 Hybrid Backup Sync version 26.2.0.938 or later.

Fix

Generation of Error Message Containing Sensitive Information

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-16029
CVE-2025-62840
ZDI-26-242

Affected Products

Hybrid Backup Sync
Qnap Hbs 3