CVE-2025-62842: CWE-73 in QNAP Systems Inc. HBS 3 Hybrid Backup Sync
CVE-2025-62842 is a high-severity vulnerability in QNAP Systems Inc. 's HBS 3 Hybrid Backup Sync version 26.1.x. It involves external control of file name or path (CWE-73), allowing an attacker with local network access to read or modify files or directories. The vulnerability has been fixed in version 26.2.0.938 and later. No known exploits are reported in the wild.
AI Analysis
Technical Summary
This vulnerability in HBS 3 Hybrid Backup Sync allows an attacker who has local network access to exploit external control over file names or paths, potentially leading to unauthorized reading or modification of files or directories. The issue is classified under CWE-73 and affects version 26.1.x of the software. The vendor has released a fixed version 26.2.0.938 and later to address this issue. The CVSS 4.0 base score is 7.0, indicating high severity with attack vector requiring physical proximity (local network), low attack complexity, and no privileges or user interaction needed.
Potential Impact
An attacker on the local network can exploit this vulnerability to read or modify files or directories on the affected system, potentially leading to unauthorized data access or tampering. This could compromise the integrity and confidentiality of backup data managed by HBS 3 Hybrid Backup Sync.
Mitigation Recommendations
Upgrade HBS 3 Hybrid Backup Sync to version 26.2.0.938 or later, where this vulnerability has been fixed. No additional mitigation steps are indicated by the vendor advisory.
CVE-2025-62842: CWE-73 in QNAP Systems Inc. HBS 3 Hybrid Backup Sync
Description
CVE-2025-62842 is a high-severity vulnerability in QNAP Systems Inc. 's HBS 3 Hybrid Backup Sync version 26.1.x. It involves external control of file name or path (CWE-73), allowing an attacker with local network access to read or modify files or directories. The vulnerability has been fixed in version 26.2.0.938 and later. No known exploits are reported in the wild.
CVSS v4.0
Score 7.0high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in HBS 3 Hybrid Backup Sync allows an attacker who has local network access to exploit external control over file names or paths, potentially leading to unauthorized reading or modification of files or directories. The issue is classified under CWE-73 and affects version 26.1.x of the software. The vendor has released a fixed version 26.2.0.938 and later to address this issue. The CVSS 4.0 base score is 7.0, indicating high severity with attack vector requiring physical proximity (local network), low attack complexity, and no privileges or user interaction needed.
Potential Impact
An attacker on the local network can exploit this vulnerability to read or modify files or directories on the affected system, potentially leading to unauthorized data access or tampering. This could compromise the integrity and confidentiality of backup data managed by HBS 3 Hybrid Backup Sync.
Mitigation Recommendations
Upgrade HBS 3 Hybrid Backup Sync to version 26.2.0.938 or later, where this vulnerability has been fixed. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- qnap
- Date Reserved
- 2025-10-24T02:43:45.372Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6957eb35db813ff03ef3559b
Added to database: 01/02/2026, 15:58:45 UTC
Last enriched: 05/26/2026, 20:15:08 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 195
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.