CVE-2025-59387
Description
An SQL injection vulnerability has been reported to affect MARS (Multi-Application Recovery Service). The remote attackers can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version: MARS (Multi-Application Recovery Service) 1.2.1.1686 and later
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in QNAP MARS (Multi-Application Recovery Service) allows remote attackers to execute arbitrary code; fixed in version 1.2.1.1686.
An SQL injection vulnerability has been discovered in MARS (Multi-Application Recovery Service) by QNAP. The flaw exists due to insufficient sanitization of user-supplied input before it is used in SQL queries. This allows an attacker to inject malicious SQL statements, leading to unauthorized code execution.
The vulnerability is remotely exploitable. An attacker can send specially crafted HTTP requests to the targeted MARS instance without requiring authentication. By manipulating input parameters, the attacker can trigger execution of arbitrary SQL commands, which may then be leveraged to execute system commands on the underlying server.
Successful exploitation enables an attacker to execute unauthorized code or commands on the affected system. This could result in full compromise of confidentiality, integrity, and availability of the MARS service and potentially the host QNAP device. The impact is critical as it allows remote unauthenticated attackers to gain control.
QNAP has addressed this issue in MARS version 1.2.1.1686 and later. Users are advised to update to the latest version immediately. Note that starting from version 1.3.x, the application has been renamed to HDP for Wordpress (MARS), but the fix covers all affected builds. No workarounds have been provided; updating is the recommended remediation [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: < 1.2.1.1686
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.