QNAP warns of critical ASP.NET flaw in its Windows backup software
ID: 70b3b0fa-f3c2-5bea-8748-e3c831c53d25
STIX ID: report--70b3b0fa-f3c2-5bea-8748-e3c831c53d25
Feed Name: Bleeping Computer
Threat Score
QNAP warns that CVE-2025-55315, a critical ASP.NET Core (Kestrel) vulnerability enabling HTTP request smuggling, affects its NetBak PC Agent and could allow low-privilege attackers to hijack credentials, bypass CSRF and other front-end protections, perform injection attacks, or cause limited DoS; users are advised to reinstall the agent or update the ASP.NET Core Runtime (Hosting Bundle) to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
