Critical .NET vulnerability affects QNAP users, specifically NetBak PC Agent software, which embeds .NET components during installation.
Microsoft has disclosed a critical vulnerability in ASP.NET Core that could allow attackers to bypass basic security measures . The vulnerability, disclosed on October 24, 2025 with the code CVE-2025-55315 , stems from HTTP Request Smuggling (CWE-444) and poses risks to systems based on outdated .NET components.

QNAP aleading provider of network-attached storage, has issued an urgent advisory, emphasizing the need for immediate updates to prevent potential exploits. The vulnerability affects ASP.NET Core, a fundamental framework for web applications, allowing authorized attackers to craft malicious HTTP requests. Successful exploitation could lead to unauthorized access to sensitive data, modifications to server files, or even limited service interruptions.
See also: Herodotus: New Android malware mimics human behavior
Although the severity has been rated as “ Important ” by Microsoft, the impacts extend to the QNAP ecosystem , particularly the NetBak PC Agent software , which integrates these .NET components during installation.

.NET Vulnerability: Technical Details and Vulnerable Systems
NetBak PC Agent, designed for backing up Windows computers to QNAP NAS devices, automatically installs Microsoft ASP.NET Core runtimes. If users have not applied recent patches, their systems remain exposed. The vulnerability exploits ambiguities in HTTP request parsing, allowing attackers to inject smuggling payloads that bypass authentication and authorization checks.
QNAP's investigation is ongoing, but the company confirms that unpatched installations of NetBak PC Agent on Windows systems are at risk . This includes versions prior to the latest updates (ASP.NET Core versions below 8.0.21 contain the vulnerability).
See also: HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass
Attackers need authorized access, which is easy for insiders or those with compromised credentials. The potential for data extraction or tampering underscores the urgent need for an update. Microsoft's patch addresses the parsing in the framework's request handling, but QNAP users must take action to ensure compatibility.

QNAP: Protection
QNAP urges all users to verify and systems their immediately. The simplest approach involves reinstalling NetBak PC Agent: uninstall the current version via Windows Settings > Apps > Installed Apps, and then download the latest installer from the official QNAP website. This process automatically downloads and installs the updated ASP.NET Core 8.0.21 runtime.
See also: Hackers target sites through outdated WordPress plugins
For those who prefer manual intervention, visit dotnet.microsoft.com/en-us/download/dotnet/8.0 and install the latest ASP.NET Core Runtime Hosting Bundle. Restart the application or system afterwards to apply the changes. QNAP also recommends monitoring for unusual network and enabling multi-factor authentication on NAS devices.
As cybersecurity threats evolve, this incident highlights the interconnected risks in software supply chains. Organizations must prioritize regular updates to protect against such vulnerabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
