ZDI-CAN-28475: ZDI-26-202: (Pwn2Own) QNAP TS-453E Hyper Data Protector Plugin query_original_file_size SQL Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of QNAP TS-453E. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2025-59389.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28475?
ZDI-CAN-28475 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-CAN-28475?
To mitigate ZDI-CAN-28475, update your QNAP TS-453E with the latest firmware provided by QNAP.
Who is affected by ZDI-CAN-28475?
Owners of QNAP TS-453E devices that use the Hyper Data Protector Plugin are affected by ZDI-CAN-28475.
Can ZDI-CAN-28475 be exploited without authentication?
Exploitation of ZDI-CAN-28475 requires authentication, making it necessary for attackers to gain access first.
What type of attack does ZDI-CAN-28475 facilitate?
ZDI-CAN-28475 facilitates SQL injection that can lead to remote code execution.