
[ZDI-26-202|CVE-2025-59389] (Pwn2Own) QNAP TS-453E Hyper Data Protector Plugin query_original_file_size SQL Injection Remote Code Execution Vulnerability (CVSS 8.0; Credit: Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)) https://www.zerodayinitiative.com/advisories/ZDI-26-202/
Post summary
A newly disclosed SQL injection vulnerability (CVE-2025-59389) in QNAP TS-453E's Hyper Data Protector Plugin can lead to remote code execution, with a CVSS score of 8.0, and has been reported by ZDI/Pwn2Own.
