logo

QNAP warns of critical ASP.NET flaw in its Windows backup software

ID: 70b3b0fa-f3c2-5bea-8748-e3c831c53d25

STIX ID: report--70b3b0fa-f3c2-5bea-8748-e3c831c53d25

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-27

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

QNAP warns that CVE-2025-55315, a critical ASP.NET Core (Kestrel) vulnerability enabling HTTP request smuggling, affects its NetBak PC Agent and could allow low-privilege attackers to hijack credentials, bypass CSRF and other front-end protections, perform injection attacks, or cause limited DoS; users are advised to reinstall the agent or update the ASP.NET Core Runtime (Hosting Bundle) to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.