Content Description:
Forwarded from National Information Security Information Sharing and Analysis Center Security Alert NISAC-200-202601-00000099
Researchers have discovered high-risk security vulnerabilities in QNAP NAS applications. Please verify and patch as soon as possible.
Qfiling contains a Path Traversal vulnerability (CVE-2025-59384). A remote unauthenticated attacker can exploit this vulnerability to read unauthorized files or system data.
MARS (Multi-Application Recovery Service) contains a SQL Injection vulnerability (CVE-2025-59387). A remote unauthenticated attacker can inject and execute unauthorized commands.
Affected Platforms:
Recommended Actions:
Reference Material:
-
-
-
-
Computer and Communication Center
Network Systems Division, Respectfully