CVE-2024-50388
published 2024-12-06CVE-2024-50388: An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITW
Exploited in the wild
EPSS
2.31%
81.5th percentile
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands.
We have already fixed the vulnerability in the following version:
HBS 3 Hybrid Backup Sync 25.1.1.673 and later
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | hybrid_backup_sync | — | — |
| qnap_systems_inc | hbs_3_hybrid_backup_sync | >= 25.1.x < 25.1.1.673 | 25.1.1.673 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is an OS command injection in HBS 3 Hybrid Backup Sync; detection should focus on unexpected OS command execution originating from the HBS 3 process on QNAP NAS devices (TS-464 and similar). ↗
- →Exploitation allows remote attackers to execute arbitrary commands and gain admin privileges without authentication; monitor for privilege escalation to admin from non-admin sessions on QNAP QTS/QuTS hero. ↗
- →The attack surface is remote and unauthenticated; monitor for anomalous inbound requests to HBS 3 Hybrid Backup Sync service endpoints on Internet-exposed QNAP NAS devices. ↗
- ·Only HBS 3 Hybrid Backup Sync versions in the 25.1.x line are confirmed vulnerable; the fix is version 25.1.1.673 and later. Ensure version checks target this specific branch. ↗
- ·Full technical exploitation details (e.g., specific vulnerable endpoint, payload structure) have not yet been published; Trend Micro ZDI has a 90-day disclosure window post-Pwn2Own before releasing full details. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.5CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
QNAP fixes seven NAS zero-day flaws exploited at Pwn2Own
blogs_bleepingcomputer·2025-11-07·CVSS 8.1
CVE-2025-62847 [HIGH] QNAP fixes seven NAS zero-day flaws exploited at Pwn2Own
## QNAP fixes seven NAS zero-day flaws exploited at Pwn2Own
## Sergiu Gatlan
QNAP has fixed seven zero-day vulnerabilities that security researchers exploited to hack QNAP network-attached storage (NAS) devices during the Pwn2Own Ireland 2025 competition.
The flaws impact QNAP's QTS and QuTS hero operating systems (CVE-2025-62847, CVE-2025-62848, CVE-2025-62849) and the company's Hyper Data Protector (CVE-2025-59389), Malware Remover (CVE-2025-11837), and HBS 3 Hybrid Backup Sync (CVE-2025-62840, CVE-2025-62842) software.
QNAP said in advisories published on Friday that the security bugs were demonstrated at Pwn2Own by the Summoning Team, DEVCORE, Team DDOS, and a CyCraft technology intern.
To patch these security flaws, QNAP recommends updating software to the latest version and chan
Bleepingcomputer
QNAP fixes NAS backup software zero-day exploited at Pwn2Own
blogs_bleepingcomputer·2024-10-29·CVSS 9.8
CVE-2024-50388 [CRITICAL] QNAP fixes NAS backup software zero-day exploited at Pwn2Own
## QNAP fixes NAS backup software zero-day exploited at Pwn2Own
## Sergiu Gatlan
QNAP has fixed a critical zero-day vulnerability exploited by security researchers on Thursday to hack a TS-464 NAS device during the Pwn2Own Ireland 2024 competition.
Tracked as CVE-2024-50388, the security flaw is caused by an OS command injection weakness in HBS 3 Hybrid Backup Sync version 25.1.x, the company's disaster recovery and data backup solution.
"An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands," QNAP said in a Tuesday security advisory.
The company has addressed the security bug in HBS 3 Hybrid Backup Sync 25.1.1.673 and later.
To update HBS 3 on your NAS dev
2024-12-06
Published
Exploited in the wild