An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

Project Subscriptions

Vendors Products
Hybrid Backup Sync Subscribe
Quts Hero Subscribe
Qutscloud Subscribe
Advisories

No advisories yet.

Fixes

Solution

QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.5.2: HBS 3 v16.0.0415 and later QTS 4.3.6: HBS 3 v3.0.210412 and later QTS 4.3.3 and 4.3.4: HBS 3 v3.0.210411 and later QuTS hero h4.5.1: HBS 3 v16.0.0419 and later QuTScloud c4.5.1~c4.5.4: HBS 3 v16.0.0419 and later


Workaround

No workaround given by the vendor.

History

Mon, 03 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:qnap:qts:4.3.3:*:*:*:*:*:*:*
cpe:2.3:a:qnap:qts:4.3.4:*:*:*:*:*:*:*
cpe:2.3:a:qnap:qts:4.5.2:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.3:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.3.4:*:*:*:*:*:*:*
cpe:2.3:o:qnap:qts:4.5.2:*:*:*:*:*:*:*

Wed, 22 Oct 2025 00:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 04 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-31'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2025-10-21T23:25:45.551Z

Reserved: 2021-03-18T00:00:00.000Z

Link: CVE-2021-28799

cve-icon Vulnrichment

Updated: 2024-08-03T21:55:11.685Z

cve-icon NVD

Status : Analyzed

Published: 2021-05-13T03:15:06.843

Modified: 2025-11-03T15:07:48.747

Link: CVE-2021-28799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses