Junglewise Threat Intelligence

CVE-2025-62842: QNAP HBS 3 Hybrid Backup Sync path traversal

CVE-2025-62842 · Severity: high · CVSS 7.8 · Published 2026-01-02

Vendors: QNAP, QNAP Systems, Inc..

Executive brief

A security vulnerability has been identified in QNAP's HBS 3 Hybrid Backup Sync, a tool used for data backup, restoration, and synchronization on QNAP NAS devices. An attacker with access to the local network could exploit this flaw to read or modify sensitive files and directories. This could lead to unauthorized data access or the corruption of critical backup information.

Technical details

An external control of file name or path vulnerability (CWE-73) exists in QNAP HBS 3 Hybrid Backup Sync versions 26.1.x and earlier. The flaw allows an attacker with local network access to manipulate file paths, leading to unauthorized file system operations. According to the CVSS metrics, the vulnerability can be exploited with low privileges and no user interaction, potentially resulting in a total loss of confidentiality, integrity, and availability for the affected data. The issue was addressed in HBS 3 Hybrid Backup Sync version 26.2.0.938.

Affected products

  • QNAP Systems Inc. HBS 3 Hybrid Backup Sync 26.1.x and earlier versions before 26.2.0.938

Timeline

  • 2025-11-08: advisory: Initial advisory published by QNAP
  • 2026-01-02: disclosed: CVE published to NVD
  • 2026-01-03: patched: QNAP updated advisory with fix details

References