Skip to content
VulniPulse

QNAP Backup (HBS) Vulnerabilities & Security Advisories

4 advisories tracked · QNAP PSIRT (security@qnap.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published QNAP advisory that VulniPulse classified as Backup (HBS), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical, 1 high, 1 low.

Android app · Google Play

Monitor QNAP CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

QNAP PSIRT (security@qnap.com CNA) via NVD

QNAP is its own CVE Numbering Authority. VulniPulse ingests QNAP's CVEs from the NVD CNA feed (security@qnap.com), grouped by their official QSA advisory, and enriches each from the security-advisory page — the vendor's severity, affected apps/OS and the fixed build. Covers QTS, QuTS hero and QuTScloud (NAS operating systems), plus QVR, Qsync, HBS 3, Netatalk, Malware Remover, License Center and Photo/Video/Music Station — QNAP NAS are a relentless ransomware target (DeadBolt, Qlocker), so an alert-hungry community.

Latest QNAP Backup (HBS) advisories

High7.8QNAP

High [CVE-2025-62842] HBS: external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later Affected product named by the advisory: HBS 3 Hybrid Backup Sync 26.1.x and earlier.

CVE-2025-62842
Backup (HBS)
Jan 2, 2026
Low3.3QNAP

Low [CVE-2025-62840] generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync

A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later Affected product named by the advisory: HBS 3 Hybrid Backup Sync 26.1.x and earlier.

CVE-2025-62840
Backup (HBS)
Jan 2, 2026
Critical9.1QNAP

Critical [CVE-2024-53695] HBS: buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later

CVE-2024-53695
Backup (HBS)
Mar 7, 2025
Critical9.8QNAP

Critical [CVE-2024-50388] HBS: OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync.

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

CVE-2024-50388
Backup (HBS)
Dec 6, 2024

← All QNAP advisories