[重要安全性通知] 发现假冒 Qfinder Pro 网站。了解详情 >

安全ID : QSA-25-46

Multiple Vulnerabilities in HBS 3 Hybrid Backup Sync (PWN2ONW 2025)


  • 发布日期 : November 8, 2025

  • 通用漏洞披露 : CVE-2025-62840 | CVE-2025-62842 | ZDI-CAN-28426 | ZDI-CAN-28428

  • 受影响产品: HBS 3 Hybrid Backup Sync 26.1.x and earlier

严重程度

严重

状态

已解决


Summary

Multiple vulnerabilities have been reported to affect HBS 3 Hybrid Backup Sync. We have already fixed the vulnerabilities in the following version:

  • CVE-2025-62840: Generation of error message containing sensitive information vulnerability, If an attacker gains local network access, they can then exploit the vulnerability to read application data.
  • CVE-2025-62842: External control of file name or path vulnerability, If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories.
Affected Product Fixed Version
HBS 3 Hybrid Backup Sync 26.1.x and earlier HBS 3 Hybrid Backup Sync 26.2.0.938 and later

Recommendation

To fix the vulnerabilities, we recommend updating HBS 3 Hybrid Backup Sync to the latest version.

  

For increased security, we also recommend users to change all passwords.

Updating HBS 3 Hybrid Backup Sync

  1. Log on to QTS or QuTS hero as an administrator.
  2. Open App Center and then click .
    A search box appears.
  3. Type "HBS 3 Hybrid Backup Sync" and then press ENTER.
    HBS 3 Hybrid Backup Sync appears in the search results.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your HBS 3 Hybrid Backup Sync is already up to date.
  5. Click OK.
    The system updates the application.

  

附件

致谢: Pwn2Own 2025 - Team DDOS

修订历史:
V1.0 (November 8, 2025) - Published
V1.1 (January 3, 2026) - Added more details

选择规格

      显示更多 隐藏更多
      open menu
      back to top