CVE-2025-62840: HBS 3 Hybrid Backup Sync
A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data.
We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62840?
CVE-2025-62840 is considered a high severity vulnerability due to the potential for sensitive information disclosure by an attacker with local network access.
How can I fix CVE-2025-62840?
To fix CVE-2025-62840, update your HBS 3 Hybrid Backup Sync to version 26.2.0.938 or later.
Who is affected by CVE-2025-62840?
CVE-2025-62840 affects users of HBS 3 Hybrid Backup Sync versions prior to 26.2.0.938.
What type of vulnerability is CVE-2025-62840?
CVE-2025-62840 is categorized as an information disclosure vulnerability due to error messages leaking sensitive data.
Can CVE-2025-62840 be exploited remotely?
No, CVE-2025-62840 requires local network access to be exploited.