Загрузка...

QNAP Warns of Dangerous ASP.NET Core Vulnerability in NetBak Agent

QNAP has confirmed that its NetBak PC Agent backup utility for Windows is affected by a critical ASP.NET Core vulnerability — CVE-2025-55315 — in Microsoft’s Kestrel web server component. This flaw enables HTTP request smuggling, allowing attackers to hijack sessions, bypass authentication, or gain unauthorized access to sensitive data.

Because NetBak PC Agent installs and relies on ASP.NET Core, systems running outdated components remain vulnerable even if the QNAP app itself is current.

✅ How to fix:

Reinstall QNAP NetBak PC Agent to update embedded ASP.NET Core.

Or manually install Microsoft’s latest .NET 8.0 runtime updates.

Restart your system or redeploy affected apps after patching.

🚨 Microsoft and QNAP both classify this as a critical issue — one of the highest-severity ASP.NET Core flaws to date.

A separate, unrelated flaw (CVE-2025-57714) affects the older NetBak Replicator utility, involving a local privilege escalation risk.

#QNAP #ASPNetCore #CVE202555315 #CyberSecurity #DataBackup #Microsoft #NetBakAgent #RequestSmuggling #Vulnerability #PatchNow

FIND US AT
https://dailysecurityreview.com/

FOLLOW US ON SOCIAL
Get updates or reach out to Get updates on our Social Media Profiles!
Twitter: https://twitter.com/securitydailyr
Facebook: https://www.facebook.com/profile.php?id=100086307206534
LinkedIn: https://www.linkedin.com/company/security-daily-review

Видео QNAP Warns of Dangerous ASP.NET Core Vulnerability in NetBak Agent канала Security Daily Review
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять