Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-62842


An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later


Published

2026-01-02T16:17:00.710

Last Modified

2026-02-05T19:03:30.353

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-73

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap hybrid_backup_sync < 26.2.0.938 Yes

References