Taiwanese vendor QNAP patched seven zero-day vulnerabilities exploited at Pwn2Own Ireland 2025. The flaws affected QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync.
The vulnerabilities addressed by the company are:
The vendor recommends that customers update the software to the latest version.
“To secure your device, we recommend regularly updating your system to the latest version to benefit from vulnerability fixes.” reads the advisory published by the company.
Below are the software versions that fix these vulnerabilities:
White-hat hackers of Summoning Team, DEVCORE, Team DDOS, and a CyCraft technology intern demonstrated the above vulnerabilities during the last Pwn2Own 2025 hacking competition.
In October 2024, QNAP addressed two vulnerabilities, tracked as CVE-2024-50388 and CVE-2024-50387, demonstrated at the Pwn2Own Ireland 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Pwn2Own)