CVE-2025-11837
Malware Remover
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 1.4%KEV nãoPoC —Patch —
Lifecycle
Jan 02, 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism.
We have already fixed the vulnerability in the following version:
Malware Remover 6.6.8.20251023 and later
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Affected products
QNAP Systems Inc. · Malware RemoverWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →