QNAP has issued an urgent warning regarding a critical vulnerability, CVE-2025-55315, affecting its NetBak PC Agent backup utility for Windows. The flaw, rooted in Microsoft’s ASP.NET Core framework and specifically the Kestrel server, enables attackers to exploit HTTP request smuggling techniques to bypass security controls, hijack credentials, and potentially access or modify sensitive backup data. The vulnerability, which carries a CVSS score of up to 9.9, requires attackers to have valid credentials but can result in unauthorized access, file modification, or limited denial-of-service conditions if exploited. QNAP’s advisory highlights that the NetBak PC Agent installs and relies on the vulnerable ASP.NET Core components, making any unpatched system susceptible to attack.
Security researchers and QNAP emphasize the importance of immediate remediation, recommending users either reinstall the NetBak PC Agent to ensure the latest ASP.NET Core runtime is deployed or manually update the ASP.NET Core components on affected systems. The vulnerability’s impact is heightened by the fact that backup servers, which often store critical data, are at risk if running outdated ASP.NET Core versions. QNAP strongly urges all users to verify their systems are up to date to prevent exploitation and safeguard backup integrity and data availability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
QNAP and Microsoft published advisories warning users about CVE-2025-55315 and recommending immediate remediation. Users were told to reinstall NetBak PC Agent or manually update to the latest .NET 8.0 runtime bundle to address the issue.
A critical vulnerability, CVE-2025-55315, was disclosed in the ASP.NET Core/Kestrel component used by QNAP's NetBak PC Agent for Windows. The flaw was rated CVSS 9.9 and could allow authenticated attackers to conduct HTTP request smuggling, bypass security controls, steal credentials, access sensitive data, modify files, or cause denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethecyberexpress.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.