ZDI-26-201: (Pwn2Own) QNAP TS-453E Hyper Data Protector Plugin Hard-Coded Credentials Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of QNAP TS-453E devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2025-59388.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-201?
ZDI-26-201 has been classified as a high-severity vulnerability due to its ability to bypass authentication.
How do I fix ZDI-26-201?
To fix ZDI-26-201, ensure that the QNAP TS-453E firmware is updated to the latest version provided by QNAP.
Who is affected by vulnerability ZDI-26-201?
All installations of the QNAP TS-453E that use the Hyper Data Protector Plugin are affected by ZDI-26-201.
What type of attack does ZDI-26-201 allow?
ZDI-26-201 allows network-adjacent attackers to exploit the vulnerability without authentication, compromising the device's security.
Is there a patch for ZDI-26-201?
Yes, QNAP has released a patch to address the vulnerability ZDI-26-201, which should be applied immediately.