Critical ASP.NET Core Vulnerability Affects QNAP NetBak PC Agent

Critical ASP.NET Core Vulnerability Affects QNAP NetBak PC Agent

First seen 2 Nov 2025, 16:14 UTC Securityaffairs.CoFeeds.Feedburner 23.6

Article Content

Browse articles
ThreatCluster

QNAP has identified a critical vulnerability (CVE-2025-55315) in its NetBak PC Agent for Windows, which is linked to the Kestrel server. This flaw enables attackers to perform HTTP request smuggling, potentially allowing them to hijack credentials, access sensitive data, modify server files, or trigger denial-of-service conditions. Users are urged to apply patches to mitigate the risk associated with this vulnerability, which has a CVSS score of 9.9.