Unrated severityNVD Advisory· Published Jan 2, 2026· Updated Jan 5, 2026
Malware Remover
CVE-2025-11837
Description
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism.
We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later
Affected products
1- QNAP Systems Inc./Malware Removerv5Range: 6.6.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- ZDI-26-198: (Pwn2Own) QNAP TS-453E malware_remover Code Injection Remote Code Execution VulnerabilityZero Day Initiative · Mar 16, 2026