CVE-2025-62842 is an external control of file name or path vulnerability affecting QNAP HBS 3 Hybrid Backup Sync versions prior to 26.2.0.938. An attacker with local network access can exploit this flaw to read or modify files and directories, leading to a high-severity impact (CVSS 7.8). While there is no public exploit code available, the vulnerability has garnered significant community discussion and media coverage, indicating active awareness. QNAP has released patches to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.2.0.938CPE matchmatch criteria | cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.