← Vulnerability feed

Vulnerability record · CVE-2021-28799 · published 13 May 2021

CVE-2021-28799: QNAP HBS 3 improper authorization allows remote login

Qnap · Hybrid Backup Sync

QNAP Hybrid Backup Sync 3 (HBS 3) contains an improper authorization flaw that lets remote attackers log in to the NAS device. The issue affects multiple HBS 3 builds across QTS 4.5.2, QTS 4.3.6, QTS 4.3.4, QTS 4.3.3, QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4, while HBS 2 and HBS 1.3 are not affected. Because the flaw bypasses authorization on a network-exposed service, it is a serious risk to internet-facing QNAP devices.

9.8 CVSS 3.1 Critical CISA KEV since 31 Mar 2022 Known ransomware use EPSS 78% · top 0.4% CWE-285 · Improper authorization
9.8CVSS 3.1 base score, v2 7.5
78%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, and a 0.7825 EPSS probability make this an actively exploited, remotely reachable authorization bypass.

What it is

QNAP Hybrid Backup Sync 3 (HBS 3) contains an improper authorization flaw that lets remote attackers log in to the NAS device. The issue affects multiple HBS 3 builds across QTS 4.5.2, QTS 4.3.6, QTS 4.3.4, QTS 4.3.3, QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4, while HBS 2 and HBS 1.3 are not affected. Because the flaw bypasses authorization on a network-exposed service, it is a serious risk to internet-facing QNAP devices.

Impact

An attacker gains the ability to log in to the affected device without valid credentials, which can lead to full control of the NAS and its data. CISA's KEV entry notes known ransomware campaign use tied to this vulnerability.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction required, so the flaw is exploitable directly over the network against the HBS 3 service. No authentication is needed to reach the vulnerable code path.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-03-31 with a due date of 2022-04-21 and flags known ransomware campaign use. EPSS gives a 30-day exploitation probability of 0.7825 (99.554th percentile), indicating very high likelihood of active exploitation.

What to do

  • Update HBS 3 to the fixed build for your platform: v16.0.0415 or later on QTS 4.5.2, v3.0.210412 or later on QTS 4.3.6, v3.0.210411 or later on QTS 4.3.4 and 4.3.3, v16.0.0419 or later on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4.
  • If immediate patching is not possible, remove HBS 3 from internet exposure and restrict access to trusted management networks.
  • Disable or block external access to the HBS 3 service and any related management ports until the update is applied.
  • Review QNAP accounts and access logs for unexpected logins or new administrative sessions.
  • Apply the vendor advisory QSA-21-13 guidance and verify the installed HBS 3 version after updating.

Detection

  • Monitor QNAP authentication and access logs for successful logins from unexpected source IPs or at unusual times.
  • Alert on HBS 3 service connections from external or untrusted networks.
  • Hunt for new or modified administrator accounts and unexpected configuration changes on QNAP NAS devices.
  • Correlate NAS log events with known ransomware indicators and outbound connections from the device.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-28799 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "QNAP NAS Improper Authorization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 21 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-28799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28809Qnap hybrid backup sync improper access control vulnerabilityAn improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attack…EPSS 16%9.5CVE-2024-50388Qnap hybrid backup sync command injection vulnerabilityAn OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attack…EPSS 2.3%7.0CVE-2025-62840Qnap hybrid backup sync error message information leak vulnerabilityA generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gai…EPSS 0.24%7.0CVE-2025-62842Qnap hybrid backup sync vulnerabilityAn external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network acces…EPSS 0.26%6.3CVE-2024-53695Qnap hybrid backup sync classic buffer overflow vulnerabilityA buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to…EPSS 0.51%8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed

Source: NIST National Vulnerability Database (record CVE-2021-28799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.