2.2
/ 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:U
Description
A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later
We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later
Basic Information
ID
CVE-2025-58465
Source
qnap
Published
Nov 7, 2025 at 15:09
Modified
Nov 7, 2025 at 15:47
Affected Product
Vendor
QNAP Systems Inc.
Product
Download Station
Version
5.10.x
Affected Versions
QNAP Systems Inc. Download Station 5.10.x
QNAP Systems Inc. Download Station 5.10.x
QNAP Systems Inc. Download Station 5.10.x