QNAP warns of critical bugs in its Windows backup software, so update now


  • CVE-2025-55315 allows HTTP request forging in ASP.NET Core (Severity 9.9/10)
  • QNAP encourages NetBak PC Agent users to patch affected ASP.NET Core components
  • Updates available via reinstallation or manual .NET 8.0 Runtime installation

QNAP is warning its customers to patch a critical ASP.NET Core vulnerability and thereby protect their NetBak PC Agent installations.

In a security advisory, the NAS device maker said Microsoft recently disclosed a bug affecting ASP.NET Core that “could allow an attacker to bypass security controls through HTTP request spoofing.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top