CVE-2025-44015

HIGH

QNAP HybridDesk Station 4.2.0-4.2.17 - OS Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: HybridDesk Station 4.2.18 and later

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0018
EPSS Percentile 38.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-78 CWE-77
Status published
Products (1)
qnap/hybriddesk_station 4.2.0 - 4.2.18
Published Aug 29, 2025
Tracked Since Feb 18, 2026