ZDI-CAN-28358: ZDI-26-201: (Pwn2Own) QNAP TS-453E Hyper Data Protector Plugin Hard-Coded Credentials Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of QNAP TS-453E devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2025-59388.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28358?
ZDI-CAN-28358 is considered a critical vulnerability due to its ability to allow authentication bypass for network-adjacent attackers.
How do I fix ZDI-CAN-28358?
To mitigate ZDI-CAN-28358, update the QNAP TS-453E device firmware to the latest version that includes security patches.
Who is affected by ZDI-CAN-28358?
Users of QNAP TS-453E devices are primarily affected by ZDI-CAN-28358 if they have the Hyper Data Protector Plugin enabled.
Can ZDI-CAN-28358 be exploited remotely?
No, ZDI-CAN-28358 requires network-adjacent access for exploitation.
What impact does ZDI-CAN-28358 have on affected systems?
ZDI-CAN-28358 allows unauthorized access to sensitive data and functionalities on QNAP TS-453E devices, potentially leading to further exploitation.