QNAP warns of critical flaw in its Windows backup software, so update now


  • CVE-2025-55315 allows HTTP request smuggling in ASP.NET Core (Severity 9.9/10)
  • QNAP urges NetBak PC Agent users to fix affected ASP.NET Core components
  • Updates available through reinstallation or manual installation of .NET 8.0 runtime

QNAP is warning customers to patch a critical ASP.NET Core vulnerability and protect their NetBak PC Agent installations.

In a security advisory, the NAS device maker said Microsoft recently disclosed a bug affecting ASP.NET Core that “could allow an attacker to bypass security controls via smuggling HTTP requests.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top