CVE-2025-57714 Details
Description
An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: NetBak Replicator 4.5.15.0807 and later
A vulnerability in QNAP NetBak Replicator versions 4.5.x has been identified, involving an unquoted search path or element. This vulnerability allows local attackers with user accounts to execute unauthorized code or commands. The issue has been resolved in NetBak Replicator version 4.5.15.0807 and later.
Users are advised to update to NetBak Replicator version 4.5.15.0807 or later. For the latest updates available for QNAP utilities, visit the QNAP Utilities page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-39 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qnap netbak replicator | >= 4.5.0.0209, < 4.5.15.0807 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 8, 2025 | Initial Analysis | [email protected] |
| Oct 3, 2025 | New CVE Received | [email protected] |