CVE-2025-59387: QNAP Systems Inc Mars Multi-Application Recovery Service

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: MARS (Multi-Application Recovery Service) 1.2.1.1686 and later

Affected products

  • QNAP Systems Inc Mars Multi-Application Recovery Service: from 1.2, before 1.2.1.1686 (fixed in 1.2.1.1686)

Published 2026-01-02. Last modified 2026-06-17.