• News/
  • https://www.bleepingcomputer.com/news/security/qnap-fixes-six-rsync-vulnerabilities-in-hbs-nas-backup-recovery-app/

QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 23, 2025
·
Updated

QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices. Rsync is an open-source file synchronization tool that supports direct file syncing via its daemon, SSH transfers via SSH, and incremental transfers that save time and bandwidth. It's widely used by many backup solutions like Rclone, DeltaCopy, and ChronoSync, as well as in cloud and server management operations and public file distribution. The flaws are tracked as CVE-2024-12084 (heap buffer overflow), CVE-2024-12085 (information leak via uninitialized stack), CVE-2024-12086 (server leaks arbitrary client files), CVE-2024-12087 (path traversal via --inc-recursive option), CVE-2024-12088 (bypass of --safe-links option), and CVE-2024-12747 (symbolic link race condition). QNAP says they affect HBS 3 Hybrid Backup Sync 25.1.x, the company's data backup and disaster recovery solution, which supports local, remote, and cloud storage services. In a security advisory released on Thursday, QNAP said it addressed these vulnerabilities in HBS 3 Hybrid Backup Sync 25.1.4.952 and advised customers to update their software to the latest version. To update the Hybrid Backup Sync installation on your NAS device, you will have to: ​​​​These Rsync flaws can be combined to create exploitation chains that lead to remote system compromise. The attackers only require anonymous read access to vulnerable servers. "When combined, the first two vulnerabil...

Read full article

Affected Software

2 affected components
QNAP HBS 3 Hybrid Backup Sync=25.1.x
QNAP HBS 3 Hybrid Backup Sync=25.1.x
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses QNAP addressing six vulnerabilities in their HBS 3 Hybrid Backup Sync application.

2

What security implications are discussed in the article?

The vulnerabilities could allow attackers to execute remote code on unpatched QNAP NAS devices.

3

What products are affected by the vulnerabilities?

The affected product is QNAP HBS 3 Hybrid Backup Sync, specifically version 25.1.x.

4

Why is it important for QNAP users to update their software?

Updating is crucial to prevent potential unauthorized access and remote code execution due to these vulnerabilities.

5

How can users protect their NAS devices from exploitation?

Users should apply the latest patches provided by QNAP for their HBS 3 software to mitigate the risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203