Critical ASP.NET Core vulnerability in QNAP NetBak PC Agent
Summary
Hide ▲
Show ▼
QNAP has warned users of a critical ASP.NET Core vulnerability affecting its NetBak PC Agent, a Windows utility for backing up data to QNAP NAS devices. The flaw, tracked as CVE-2025-55315, allows attackers with low privileges to hijack credentials or bypass security controls via HTTP request smuggling. Users are advised to update their systems to mitigate the risk. The vulnerability impacts systems running NetBak PC Agent due to its dependency on Microsoft ASP.NET Core components. Successful exploitation could lead to unauthorized access, data modification, or denial-of-service conditions.
Timeline
-
27.10.2025 18:55 1 articles · 23h ago
QNAP issues warning about critical ASP.NET Core vulnerability in NetBak PC Agent
QNAP has alerted users of a critical ASP.NET Core vulnerability affecting its NetBak PC Agent. The flaw, CVE-2025-55315, allows attackers to hijack credentials or bypass security controls. Users are advised to update their systems to mitigate the risk. The vulnerability impacts systems running NetBak PC Agent due to its dependency on Microsoft ASP.NET Core components. Successful exploitation could lead to unauthorized access, data modification, or denial-of-service conditions.
Show sources
- QNAP warns of critical ASP.NET flaw in its Windows backup software — www.bleepingcomputer.com — 27.10.2025 18:55
Information Snippets
-
The vulnerability, CVE-2025-55315, affects the Kestrel ASP.NET Core web server.
First reported: 27.10.2025 18:551 source, 1 articleShow sources
- QNAP warns of critical ASP.NET flaw in its Windows backup software — www.bleepingcomputer.com — 27.10.2025 18:55
-
The flaw enables attackers with low privileges to hijack credentials or bypass security controls.
First reported: 27.10.2025 18:551 source, 1 articleShow sources
- QNAP warns of critical ASP.NET flaw in its Windows backup software — www.bleepingcomputer.com — 27.10.2025 18:55
-
NetBak PC Agent installs and depends on Microsoft ASP.NET Core components.
First reported: 27.10.2025 18:551 source, 1 articleShow sources
- QNAP warns of critical ASP.NET flaw in its Windows backup software — www.bleepingcomputer.com — 27.10.2025 18:55
-
Users are advised to reinstall NetBak PC Agent or manually update ASP.NET Core to mitigate the risk.
First reported: 27.10.2025 18:551 source, 1 articleShow sources
- QNAP warns of critical ASP.NET flaw in its Windows backup software — www.bleepingcomputer.com — 27.10.2025 18:55
-
Successful exploitation could result in unauthorized access, data modification, or denial-of-service conditions.
First reported: 27.10.2025 18:551 source, 1 articleShow sources
- QNAP warns of critical ASP.NET flaw in its Windows backup software — www.bleepingcomputer.com — 27.10.2025 18:55