HomeSecurityVulnerability in QNAP NetBak Replicator allows unauthorized code execution

Vulnerability in QNAP NetBak Replicator allows unauthorized code execution

QNAP has released a security advisory describing a vulnerability in the NetBak Replicator, which could allow local attackers to execute unauthorized code.

See also: QNAP fixes vulnerabilities found in Pwn2Own

QNAP NetBak Replicator

The vulnerability, identified as CVE-2025-57714, has been rated “Important” and affects specific versions of the backup and recovery software. The company has already issued a patch and is urging users to update their systems to prevent potential exploitation.

This vulnerability results from an unquoted search path or element within the NetBak Replicator software. This type of vulnerability occurs when the path to an executable file is not properly enclosed in quotes.

If a local attacker has already gained access to a user account on the system, they can place a malicious executable file in a parent directory of the legitimate program's path. The operating system can then mistakenly execute the malicious file instead of the intended one, leading to unauthorized code execution with the privileges of the running application.

See also: QNAP fixed critical vulnerabilities in various products

QNAP1

The vulnerability specifically affects versions 4.5.x of NetBak Replicator. According to the advisory released on October 4, 2025, a successful exploit requires an attacker to have prior access to a user account locally. From there, they can leverage the non-login search path to execute arbitrary commands or code. This could allow the attacker to escalate privileges, install persistent malware, or manipulate data on the compromised system.

While the attack requires local access, it represents a significant risk in multi-user environments or as a privilege escalation technique after exploitation.

QNAP has addressed the security vulnerability in version 4.5.15.0807 and all subsequent versions. The company strongly recommends that all users of affected versions of the software update to the latest released version immediately to protect their devices from potential attacks.

See also: QNAP fixes vulnerability presented at Pwn2Own Ireland 2024

Vulnerability in QNAP NetBak Replicator allows unauthorized code execution

The discovery of this vulnerability is credited to Kazuma Matsumoto of GMO Cybersecurity from IERAE, Inc.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS