An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later
History

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Qnap
Qnap malware Remover
CPEs cpe:2.3:a:qnap:malware_remover:*:*:*:*:*:*:*:*
Vendors & Products Qnap
Qnap malware Remover
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 06 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later
Title Malware Remover
First Time appeared Qnap Systems Inc.
Qnap Systems Inc. malware Remover
Weaknesses CWE-94
CPEs cpe:2.3:a:qnap_systems_inc.:malware_remover:*:*:*:*:*:*:*:*
Vendors & Products Qnap Systems Inc.
Qnap Systems Inc. malware Remover
References
Metrics cvssV4_0

{'score': 8.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published: 2026-01-02T15:51:28.839Z

Updated: 2026-01-05T20:38:25.200Z

Reserved: 2025-10-16T05:24:28.428Z

Link: CVE-2025-11837

cve-icon Vulnrichment

Updated: 2026-01-05T20:33:38.398Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-02T16:15:48.403

Modified: 2026-01-22T18:28:22.310

Link: CVE-2025-11837

cve-icon Redhat

No data.