• News/
  • https://www.bleepingcomputer.com/news/security/qnap-fixes-seven-nas-zero-day-vulnerabilities-exploited-at-pwn2own/

QNAP fixes seven NAS zero-day flaws exploited at Pwn2Own

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 7, 2025
·
Updated

QNAP has fixed seven zero-day vulnerabilities that security researchers exploited to hack QNAP network-attached storage (NAS) devices during the Pwn2Own Ireland 2025 competition. The flaws impact QNAP's QTS and QuTS hero operating systems (CVE-2025-62847, CVE-2025-62848, CVE-2025-62849) and the company's Hyper Data Protector (CVE-2025-59389), Malware Remover (CVE-2025-11837), and HBS 3 Hybrid Backup Sync (CVE-2025-62840, CVE-2025-62842) software. QNAP said in advisories published on Friday that the security bugs were demonstrated at Pwn2Own by the Summoning Team, DEVCORE, Team DDOS, and a CyCraft technology intern. To patch these security flaws, QNAP recommends updating software to the latest version and changing all passwords for increased security. QNAP has fixed all these vulnerabilities in the following software versions: Users who want to update their OS to log in to QTS or QuTS Hero as an administrator should go to Control Panel > System > Firmware Update and click "Check for Update" under Live Update. To update the vulnerable apps, first log in to QTS or QuTS hero as an admin, then open the App Center and click the search button. Type the name of the app you want to update and press ENTER. In the search results, click "Update," and then confirm the action by clicking "OK" on the confirmation message that appears. "To secure your device, we recommend regularly updating your system to the latest version to benefit from vulnerability fixes. You can check the product supp...

Read full article

Affected Software

5 affected components
QNAP QTS
QNAP QuTS hero
QNAP Hyper Data Protector
QNAP Malware Remover
QNAP HBS 3 Hybrid Backup Sync
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What are the main vulnerabilities addressed in this article?

The article discusses seven zero-day vulnerabilities exploited in QNAP NAS devices at the Pwn2Own competition.

2

Which QNAP products are impacted by these vulnerabilities?

The affected products include QNAP QTS, QuTS hero, Hyper Data Protector, Malware Remover, and HBS 3 Hybrid Backup Sync.

3

What event led to the discovery of these vulnerabilities?

The vulnerabilities were exploited during the Pwn2Own Ireland 2025 hacking competition.

4

What actions has QNAP taken in response to these vulnerabilities?

QNAP has released fixes to address the seven zero-day flaws in their systems.

5

What are the potential security implications of these vulnerabilities?

Exploitation of these vulnerabilities could allow attackers unauthorized access to sensitive data on QNAP NAS devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203