logo

QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app

ID: a754697b-e965-5960-85c6-ce90a8d7c3bc

STIX ID: report--a754697b-e965-5960-85c6-ce90a8d7c3bc

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-23

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

QNAP released an advisory fixing six rsync vulnerabilities (CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747) in HBS 3 Hybrid Backup Sync that together can enable remote code execution, information leaks, path traversal, and symlink race attacks; customers are urged to update to HBS 3 25.1.4.952 to mitigate risk, and CERT/CC noted that attackers only need anonymous read access while Shodan shows hundreds of thousands of exposed rsync servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.