CVE-2025-62842
Unknown
Unknown - Not Provided
Path Traversal Vulnerability in HBS 3 Hybrid Backup Sync Allows File Access
Publication date: 2026-01-02
Last updated on: 2026-02-05
Assigner: QNAP Systems, Inc.
Description
Description
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories.
We have already fixed the vulnerability in the following version:
HBS 3 Hybrid Backup Sync 26.2.0.938 and later
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qnap | hbs_3_hybrid_backup_sync | From 26.2.0.938 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |