⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
Severity
9.5CRITICAL
EPSS
6.0%
top 9.30%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 6

Description

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected Packages2 packages

CVEListV5qnap_systems_inc./hbs_3_hybrid_backup_sync25.1.x25.1.1.673
NVDqnap/hybrid_backup_sync25.1.0.627

🔴Vulnerability Details

2
GHSA
GHSA-m3fm-4744-qmhg: An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync2024-12-06
CVEList
HBS 3 Hybrid Backup Sync2024-12-06

🕵️Threat Intelligence

1
Bleepingcomputer
QNAP fixes NAS backup software zero-day exploited at Pwn2Own2024-10-29
CVE-2024-50388 (CRITICAL CVSS 9.5) | An OS command injection vulnerabili | cvebase.io