QNAP Urges Critical ASP.NET Core Patch for NetBak PC Agent

28 Oct 2025

QNAP has issued an urgent advisory for users to patch a significant vulnerability in ASP.NET Core, affecting NetBak PC Agent. The flaw, identified as CVE-2025-55315, is an HTTP request smuggling vulnerability in the Kestrel web server with a CVSS score of 9.9. This security issue could allow unauthorized access or modifications to server data, and potential denial-of-service attacks.

Understanding the Vulnerability

The CVE-2025-55315 vulnerability poses a critical risk due to its ability to let unauthenticated attackers transmit additional malicious HTTP requests within a primary request. This can result in unauthorized data access or modifications on affected servers. The vulnerability impacts systems where NetBak PC Agent depends on Microsoft ASP.NET Core components during installation.

Recommended Update Actions

QNAP strongly recommends users to update their systems to mitigate this vulnerability. There are two main ways to update:

  • Reinstall NetBak PC Agent by uninstalling the existing version and downloading the latest release.
  • Manually update ASP.NET Core by downloading the latest .NET 8.0 ASP.NET Core Runtime (Hosting Bundle) as of 2025-10-01, the version is 8.0.21, and installing it on the system.

After the update, users should restart either the application or the complete system to ensure all changes take effect.

Additional Security Updates

Microsoft has also rolled out crucial security updates for several components, including Visual Studio 2022, ASP.NET Core 2.3, 8.0, and 9.0. Updates are likewise available for the Microsoft.AspNetCore.Server.Kestrel.Core package for versions of ASP.NET Core 2.x.

QNAP emphasizes the importance of these updates to safeguard against potential exploits targeting this high-severity vulnerability in the Kestrel server utilized by ASP.NET Core.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6271504
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1227347
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
479521
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
451685
downloads

News and reviews for Desktop Windows

QNAP Urges Critical ASP.NET Core Patch for NetBak PC Agent

QNAP advises users to patch a critical ASP.NET Core vulnerability affecting NetBak PC Agent to prevent potential attacks.

Read more

Evercore Heroes Ascension to Shut Down After Early Access

Evercore Heroes shuts down on 2025-10-30 after one month of Early Access due to low player interest.

Read more

The Florist Announced: Survival Horror Game by Unclear Games

The Florist by Unclear Games is set for a 2026 release on PC and consoles, featuring versatile gameplay with Jessica Park navigating Joycliffe.

Read more

Scream Fest: Steam's Halloween Sale Offers Up to 90% Off

Steam's Scream Fest runs October 27 to November 3, offering deep discounts on horror games. Top deals include Alien: Isolation and The Walking Dead.

Read more

Bully Online Mod Launches, Targets 2026 Full Release

Early access to Bully Online for backers begins in December, offering a unique multiplayer experience ahead of its planned 2026 release.

Read more

More Nintendo DS Games Could Enhance Steam Experience

Dementium: The Ward prompts calls for more Nintendo DS ports on Steam amid rising handheld gameplay.

Read more

Windows 10 Users Can Enroll in Extended Security Updates

Windows 10 users can enroll in Microsoft’s Extended Security Updates to stay secure through 2026, using OneDrive or Microsoft Rewards points.

Read more

Bloodhunt Shutdown Set for April 2026

Sharkmob will shut down Bloodhunt servers on 2026-04-28 due to low player counts, affecting the vampire battle royale genre.

Read more

Steam Scream Fest Discounts Horror and Non-Horror Games

Steam Scream Fest offers game discounts until 2023-11-03, featuring Inscryption for $8 and Mouthwashing for $9.09.

Read more

RedSec Battle Royale Releases on 2025-10-28 Worldwide

RedSec, the free-to-play battle royale by Ripple Effect, launches on 2025-10-28, marking an exciting development in the Battlefield series.

Read more