A critical vulnerability, tracked as CVE-2025-55315, has been identified in QNAP’s NetBak PC Agent, stemming from a flaw within Microsoft’s ASP.NET Core framework. The issue allows attackers to exploit HTTP Request Smuggling (CWE-444) techniques to bypass essential security controls, potentially granting unauthorized access to sensitive backup data and system files.
First seen on thecyberexpress.com
Jump to article: thecyberexpress.com/cve-2025-55315-hits-qnap-netbak-pc-agent/
![]()

