# CVE-2025-62840

## Summary

- **CVE ID:** CVE-2025-62840
- **Severity:** HIGH
- **CVSS Score:** 7 (CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-209
- **Published:** Jan 2, 2026
- **Last Modified:** Mar 12, 2026

## Description

A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data.

We have already fixed the vulnerability in the following version:
HBS 3 Hybrid Backup Sync 26.2.0.938 and later

## Affected Products

- QNAP Systems Inc. — HBS 3 Hybrid Backup Sync (26.1.x)

## References

- [CNA](https://www.qnap.com/en/security-advisory/qsa-25-46)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 14.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._