CVE-2025-57714
BaseFortify
Publication date: 2025-10-03
Last updated on: 2025-12-08
Assigner: QNAP Systems, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qnap | netbak_replicator | From 4.5.0.0209 (inc) to 4.5.15.0807 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-428 | The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an unquoted search path or element issue in NetBak Replicator. It allows a local attacker who has a user account on the system to execute unauthorized code or commands by exploiting the way the software searches for executable files without properly quoting the path elements.
How can this vulnerability impact me? :
If exploited, this vulnerability can allow a local attacker to run unauthorized code or commands on your system, potentially leading to system compromise, data loss, or other malicious activities.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update NetBak Replicator to version 4.5.15.0807 or later, where the issue has been fixed.