QNAP Advises Users Patch Critical ASP .NET Core Flaw Affecting NetBak PC Agent CVE-2025-55315
H-ISAC TLP White Vulnerability Bulletin: QNAP Advises Users Patch Critical ASP .NET Core Flaw Affecting NetBak PC Agent (CVE-2025-55315)
October 27, 2025
On October 24, 2025, QNAP issued a security advisory regarding a critical vulnerability, CVE-2025-55315, in the Microsoft ASP .NET Core component installed by and utilized within its NetBak PC Agent application.
This vulnerability is an HTTP Request Smuggling flaw (CWE-444) that could allow an authenticated attacker to bypass security controls by sending specially crafted HTTP requests to the web server. QNAP strongly recommends that users update the ASP .NET Core Runtime on their Windows systems as soon as possible by installing the latest versions of NetBak PC Agent or manually applying the Microsoft patch.
Health-ISAC is sharing this to increase situational awareness and encourage organizations to assess their level of risk to this vulnerability.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: