NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgate
Netgate data Backup |
|
| Vendors & Products |
Netgate
Netgate data Backup |
Wed, 04 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations. | |
| Title | NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-04T23:15:49.196Z
Updated: 2026-02-04T23:15:49.196Z
Reserved: 2026-01-06T16:07:08.525Z
Link: CVE-2019-25271
No data.
Status : Awaiting Analysis
Published: 2026-02-05T00:15:51.343
Modified: 2026-02-05T14:57:20.563
Link: CVE-2019-25271
No data.
ReportizFlow