CVE-2025-59388

CRITICAL

Hyper Data Protector <2.3.1.455 - Auth Bypass

Title source: llm

Description

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later

Scores

CVSS v3 9.8
EPSS 0.0019
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-259
Status published
Products (2)
qnap/hyper_data_protector 2.2.0.284 - 2.3.1.455
QNAP Systems Inc./Hyper Data Protector 2.3.x - 2.3.1.455
Published Mar 12, 2026
Tracked Since Mar 12, 2026