CVE-2024-50388: HBS 3 Hybrid Backup Sync
Published Dec 6, 2024
·Updated
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands.
We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later
Affected Software
2 affected components
HBS Hybrid Backup Sync<25.1.1.673
QNAP Hybrid Backup Sync=25.1.0.627
Remediation
Information
We have already fixed the vulnerability in the following version:
HBS 3 Hybrid Backup Sync 25.1.1.673 and later
Event History
Oct 29, 2024
News Published
via BleepingComputer·05:35 PM
News Published
via BleepingComputer·05:36 PM
Dec 6, 2024
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 7, 2025
News Published
via BleepingComputer·06:24 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-50388?
CVE-2024-50388 has a high severity rating due to its potential for remote command execution by attackers.
2
How do I fix CVE-2024-50388?
To mitigate CVE-2024-50388, you should upgrade to HBS 3 Hybrid Backup Sync version 25.1.1.673 or later.
3
What systems are affected by CVE-2024-50388?
CVE-2024-50388 affects HBS 3 Hybrid Backup Sync versions before 25.1.1.673.
4
What type of vulnerability is CVE-2024-50388?
CVE-2024-50388 is classified as an OS command injection vulnerability.
5
Can CVE-2024-50388 be exploited remotely?
Yes, CVE-2024-50388 can be exploited remotely by attackers to execute commands.