PT-2026-5804 · Netgate · Netgate Data Backup

Published

2026-02-04

·

Updated

2026-02-05

·

CVE-2019-25271

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGATE Data Backup version 3.0.620
Description The software contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. This allows attackers to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.
Recommendations Apply appropriate quoting to the service path configuration for the NGDatBckpSrv Windows service.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-25271

Affected Products

Netgate Data Backup