CVE-2025-62840: QNAP Hybrid Backup Sync
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later
Affected products
- QNAP Hybrid Backup Sync: before 26.2.0.938 (fixed in 26.2.0.938)
Published 2026-01-02. Last modified 2026-06-17.