
[ZDI-26-216|CVE-2025-62847] (Pwn2Own) QNAP TS-453E smbd domain_name Argument Injection Authentication Bypass Vulnerability (CVSS 6.3; Credit: @YingMuo , @ljp_tw , @h3xr4bb1t , and @nella17tw of DEVCORE Research Team) https://www.zerodayinitiative.com/advisories/ZDI-26-216/
Post summary
This advisory discloses a new argument injection authentication bypass vulnerability (CVE-2025-62847) affecting QNAP TS-453E with a CVSS score of 6.3, crediting the DEVCORE Research Team and linking to a ZeroDay Initiative advisory.

