[重要安全性通知] 发现假冒 Qfinder Pro 网站。了解详情 >

安全ID : QSA-25-48

Multiple Vulnerabilities in Hyper Data Protector (PWN2OWN 2025)


  • 发布日期 : November 8, 2025

  • 通用漏洞披露 : CVE-2025-59389 | ZDI-CAN-28475 | CVE-2025-59388 | ZDI-CAN-28358

  • 受影响产品: Hyper Data Protector 2.2.x

严重程度

严重

状态

已解决


Summary

Multiple vulnerabilities have been reported to affect Hyper Data Protector.

  • CVE-2025-59389: If exploited, remote attackers can exploit the SQL injection vulnerability to execute unauthorized code or commands.
  • CVE-2025-59388: If exploited, remote attackers can exploit the use of hard-coded password vulnerability to gain unauthorized access.

We have already fixed the vulnerabilities in the following version:

Affected Product Fixed Version
Hyper Data Protector 2.2.x Hyper Data Protector 2.3.1.455 and later

Recommendation

To fix the vulnerability, we recommend updating Hyper Data Protector to the latest version.

Updating Hyper Data Protector

  1. Log on to QTS or QuTS hero as an administrator.
  2. Open App Center and then click .
    A search box appears.
  3. Type "Hyper Data Protector" and then press ENTER.
    Hyper Data Protector appears in the search results.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your Hyper Data Protector is already up to date.
  5. Click OK.
    The system updates the application.

  

附件

致谢: Pwn2Own 2025 - Summoning Team

修订历史:
V1.0 (November 8, 2025) - Published
V1.1 (January 3, 2026) - Added more details
V1.2 (March 12, 2026) - Update ZDI IDs

选择规格

      显示更多 隐藏更多
      open menu
      back to top