CVE 2.3 LOW

Download Station_CVE-2025-58463

2.3 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:U

Description

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.

We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later

Basic Information

ID CVE-2025-58463
Source qnap
Published Nov 7, 2025 at 15:10
Modified Nov 7, 2025 at 16:11

Affected Product

Vendor QNAP Systems Inc.
Product Download Station
Version 5.10.x
Affected Versions QNAP Systems Inc. Download Station 5.10.x
QNAP Systems Inc. Download Station 5.10.x

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.