---
id: CVE-2025-62842
title: >-
  An external control of file name or path vulnerability has been reported to
  affect HBS 3 Hybrid Backup Sync
summary: >-
  An external control of file name or path vulnerability has been reported to
  affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access,
  they can then exploit the vulnerability to read or modify files or
  directories.


  We h…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-73
vendor: qnap
product: hybrid_backup_sync
affected:
  - hybrid_backup_sync < 26.2.0.938
patched:
  - hybrid_backup_sync 26.2.0.938
published: '2026-01-02'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62842'
references:
  - url: 'https://www.qnap.com/en/security-advisory/qsa-25-46'
    label: security@qnapsecurity.com.tw
tags:
  - nvd
epss: 0.00261
epssPercentile: 0.15932
ingestedAt: '2026-07-25T11:55:02.441Z'
---

## Overview

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories.

We have already fixed the vulnerability in the following version:
HBS 3 Hybrid Backup Sync 26.2.0.938 and later

## Affected

- `hybrid_backup_sync < 26.2.0.938`

## Remediation

Upgrade past the affected range:

- `hybrid_backup_sync 26.2.0.938`
