QNAP fixed multiple zero-days in its software demonstrated at Pwn2Own 2025
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-50387 | A SQL injection vulnerability has been reported to affect several QNAP operating system versions. A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and later NVD description · AI analysis pending | 10.0 | 10% |
| — | ||
| CVE-2024-50388 | An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later NVD description · AI analysis pending | 9.5 | 2% |
| — | ||
| CVE-2025-11837 | An improper control of generation of code vulnerability has been reported to affect Malware Remover. An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2025-59389 | An SQL injection vulnerability has been reported to affect Hyper Data Protector. An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: Hyper Data Protector 2.2.4.1 and later NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2025-62842 +1 in the same advisory: …62840 | An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later NVD description · AI analysis pending | 7.0 | <1% |
| — | ||
| CVE-2025-62848 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later NVD description · AI analysis pending | 8.1 group max | <1% |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 2.2.4.1 | rsions that fix these vulnerabilities: Hyper Data Protector 2.2.4.1 and later Malware Remover 6.6.8.20251023 and later HBS 3 Hy |
Full article241 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 10, 2025

QNAP patched seven zero-days used at Pwn2Own 2025 affecting QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3.
Taiwanese vendor QNAP patched seven zero-day vulnerabilities exploited at Pwn2Own Ireland 2025. The flaws affected QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync.
The vulnerabilities addressed by the company are:
- CVE-2025-62847 – CVE-2025-62848 – CVE-2025-62849 in QNAP’s QTS and QuTS hero operating systems;
- CVE-2025-11837 in Malware Remover;
- CVE-2025-59389 in Hyper Data Protector;
- CVE-2025-62840 – CVE-2025-62842 in HBS 3 Hybrid Backup Sync software.
The vendor recommends that customers update the software to the latest version.
“To secure your device, we recommend regularly updating your system to the latest version to benefit from vulnerability fixes.” reads the advisory published by the company.
Below are the software versions that fix these vulnerabilities:
- Hyper Data Protector 2.2.4.1 and later
- Malware Remover 6.6.8.20251023 and later
- HBS 3 Hybrid Backup Sync 26.2.0.938 and later
- QTS 5.2.7.3297 build 20251024 and later
- QuTS hero h5.2.7.3297 build 20251024 and later
- QuTS hero h5.3.1.3292 build 20251024 and later
White-hat hackers of Summoning Team, DEVCORE, Team DDOS, and a CyCraft technology intern demonstrated the above vulnerabilities during the last Pwn2Own 2025 hacking competition.
In October 2024, QNAP addressed two vulnerabilities, tracked as CVE-2024-50388 and CVE-2024-50387, demonstrated at the Pwn2Own Ireland 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Pwn2Own)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184396/hacking/qnap-fixed-multiple-zero-days-in-its-software-demonstrated-at-pwn2own-2025.html