A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later
History

Fri, 02 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later
Title HBS 3 Hybrid Backup Sync
First Time appeared Qnap Systems Inc.
Qnap Systems Inc. hbs 3 Hybrid Backup Sync
Weaknesses CWE-209
CPEs cpe:2.3:a:qnap_systems_inc.:hbs_3_hybrid_backup_sync:*:*:*:*:*:*:*:*
Vendors & Products Qnap Systems Inc.
Qnap Systems Inc. hbs 3 Hybrid Backup Sync
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-01-02T15:51:34.972Z

Reserved: 2025-10-24T02:43:45.372Z

Link: CVE-2025-62840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-02T16:17:00.573

Modified: 2026-01-02T16:45:26.640

Link: CVE-2025-62840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.