CVE-2025-62840 is a sensitive information disclosure vulnerability in QNAP HBS 3 Hybrid Backup Sync, specifically versions prior to 26.2.0.938. An attacker with local network access can exploit this flaw to read application data due to error messages containing sensitive information. Rated with a CVSS score of 3.3 (LOW), the vulnerability requires local access and has a limited impact of confidentiality loss. While there is no public exploit code or Metasploit/Nuclei modules available, it has garnered significant community discussion and media coverage, including reports of it being exploited at Pwn2Own.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.2.0.938CPE matchmatch criteria | cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.