QNAP Advises Users Patch Critical ASP .NET Core Flaw Affecting NetBak PC Agent CVE-2025-55315

H-ISAC TLP White Vulnerability Bulletin: QNAP Advises Users Patch Critical ASP .NET Core Flaw Affecting NetBak PC Agent (CVE-2025-55315) 
October 27, 2025

On October 24, 2025, QNAP issued a security advisory regarding a critical vulnerability, CVE-2025-55315, in the Microsoft ASP .NET Core component installed by and utilized within its NetBak PC Agent application.

This vulnerability is an HTTP Request Smuggling flaw (CWE-444) that could allow an authenticated attacker to bypass security controls by sending specially crafted HTTP requests to the web server. QNAP strongly recommends that users update the ASP .NET Core Runtime on their Windows systems as soon as possible by installing the latest versions of NetBak PC Agent or manually applying the Microsoft patch.

Health-ISAC is sharing this to increase situational awareness and encourage organizations to assess their level of risk to this vulnerability.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272