ZeroHour
Security Affairspublished ()ingested @securityaffairs

QNAP fixed multiple zero-days in its software demonstrated at Pwn2Own 2025

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-50387
A SQL injection vulnerability has been reported to affect several QNAP operating system versions.

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and later

NVD description · AI analysis pending
10.010%
  • qnap smb service
CVE-2024-50388
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

NVD description · AI analysis pending
9.52%
  • qnap hybrid backup sync
CVE-2025-11837
An improper control of generation of code vulnerability has been reported to affect Malware Remover.

An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later

NVD description · AI analysis pending
8.11%
  • qnap malware remover
CVE-2025-59389
An SQL injection vulnerability has been reported to affect Hyper Data Protector.

An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: Hyper Data Protector 2.2.4.1 and later

NVD description · AI analysis pending
8.1<1%
  • qnap hyper data protector
CVE-2025-62842
+1 in the same advisory: …62840
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later

NVD description · AI analysis pending
7.0<1%
  • qnap hybrid backup sync
CVE-2025-62848
+2 in the same advisory: …62847 …62849
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

NVD description · AI analysis pending
8.1
group max
<1%
  • qnap qts
  • qnap quts hero

Indicators of compromiseAll →

TypeIndicatorContext
ipv42.2.4.1rsions that fix these vulnerabilities: Hyper Data Protector 2.2.4.1 and later Malware Remover 6.6.8.20251023 and later HBS 3 Hy
Full article241 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 10, 2025

QNAP patched seven zero-days used at Pwn2Own 2025 affecting QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3.

Taiwanese vendor QNAP patched seven zero-day vulnerabilities exploited at Pwn2Own Ireland 2025. The flaws affected QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync.

The vulnerabilities addressed by the company are:

The vendor recommends that customers update the software to the latest version.

“To secure your device, we recommend regularly updating your system to the latest version to benefit from vulnerability fixes.” reads the advisory published by the company.

Below are the software versions that fix these vulnerabilities:

  • Hyper Data Protector 2.2.4.1 and later
  • Malware Remover 6.6.8.20251023 and later
  • HBS 3 Hybrid Backup Sync 26.2.0.938 and later
  • QTS 5.2.7.3297 build 20251024 and later
  • QuTS hero h5.2.7.3297 build 20251024 and later
  • QuTS hero h5.3.1.3292 build 20251024 and later

White-hat hackers of Summoning Team, DEVCORE, Team DDOS, and a CyCraft technology intern demonstrated the above vulnerabilities during the last Pwn2Own 2025 hacking competition.

In October 2024, QNAP addressed two vulnerabilities, tracked as CVE-2024-50388 and CVE-2024-50387, demonstrated at the Pwn2Own Ireland 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pwn2Own)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184396/hacking/qnap-fixed-multiple-zero-days-in-its-software-demonstrated-at-pwn2own-2025.html