Drooid Logo
Back to today’s briefing

Story perspectives

Critical ASP.NET Vulnerability Threatens QNAP Users—Update Now!

10/28/2025

35 8

1 of 1

Story summary
  • CVE-2025-55315 is a critical vulnerability in Microsoft ASP.NET Core that enables authenticated attackers to exploit HTTP Request Smuggling to gain unauthorized access or cause disruption.
  • The flaw affects QNAP's NetBak PC Agent software.
  • The CVSS score is 9.9, signaling high risk for organizations using outdated ASP.NET components.
  • QNAP urges updating by reinstalling NetBak PC Agent or applying ASP.NET Core runtime 8.0.21.
  • Regular patching is essential to safeguard systems.