CVE-2025-59388Disclosure(qnap / hyper_data_protector)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-259

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hyper_data_protector

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
hyper_data_protector

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-18: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-18: 103-1203-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-03-181
Disclosure1
Full discourse3 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-201|CVE-2025-59388] (Pwn2Own) QNAP TS-453E Hyper Data Protector Plugin Hard-Coded Credentials Authentication Bypass Vulnerability (CVSS 6.3; Credit: Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)) https://www.zerodayinitiative.com/advisories/ZDI-26-201/

    Post summary

    An advisory discloses a hard‑coded credentials authentication bypass flaw in the QNAP TS‑453E Hyper Data Protector Plugin, rated CVSS 6.3, with no current patch or active exploitation reported.

    0201111.4K
    5.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-59388 📊 Severity: 6.6 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-59388 #CVE-2025-59388 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/205F09ZP9s

    Post summary

    The tweet is a straightforward disclosure of CVE-2025-59388, noting its severity and affected products, with no additional technical or exploit details.

    00000100
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59388 A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthori… https://www.cve.org/CVERecord?id=CVE-2025-59388

    Post summary

    The text reports that CVE‑2025‑59388, a hard‑coded password vulnerability, affects Hyper Data Protector and could allow remote attackers to gain unauthorized access. No proof of concept, exploit code, patch information, or evidence of active exploitation is provided.

    00000136
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqnaphyper_data_protector---

Explore more