OS Command Injection Vulnerability in HBS 3 Hybrid Backup Sync by QNAP
CVE-2024-50388
Currently unrated
Summary
An OS command injection vulnerability has been identified in HBS 3 Hybrid Backup Sync, allowing remote attackers to execute arbitrary commands on the affected system. Successful exploitation could compromise the integrity and security of the application and potentially lead to unauthorized access to sensitive data. QNAP has addressed this vulnerability in version 25.1.1.673 and later, urging all users to update their software to mitigate the risks associated with this issue.
References
Timeline
Vulnerability published