CVE-2025-59388

CRITICAL

Hyper Data Protector <2.3.1.455 - Auth Bypass

Title source: llm
STIX 2.1

Description

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-259
Status published
Products (2)
qnap/hyper_data_protector 2.2.0.284 - 2.3.1.455
QNAP Systems Inc./Hyper Data Protector 2.3.x - 2.3.1.455
Published Mar 12, 2026
Tracked Since Mar 12, 2026