← Back

CVE-2025-58463

nvd nist
Published: Nov 7, 2025Modified: Nov 17, 2025

JSON object

Loading...
2.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@qnapsecurity.com.tw (Secondary)

Description

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Download Station 5.10.0.305 ( 2025/09/16 ) and later Download Station 5.10.0.304 ( 2025/09/08 ) and later

Affected (2)

1 product
Download Station
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 5.10.0.291
Running on/withPlatform Versions
Qnap
Quts Hero
Version h5.2.1.2929 build_20241025
Qnap
Quts Hero
Version h5.2.1.2940 build_20241105
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10.0.291 to 5.10.0.305
Running on/withPlatform Versions
Qnap
Qts
Version 5.2.1.2930 build_20241025

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.