4.9

CVE-2025-58463

Medienbericht

Download Station

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.

We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Download Station Version 5.10.0.291
   Qnap ≫ Quts Hero Version h5.2.1.2929 Update build_20241025
   Qnap ≫ Quts Hero Version h5.2.1.2940 Update build_20241105
Qnap ≫ Download Station Version >= 5.10.0.291 < 5.10.0.305
   Qnap ≫ Qts Version 5.2.1.2930 Update build_20241025
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.47% 0.38
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
security@qnapsecurity.com.tw 2.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-23 Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
10.11.2025 09:04
https://www.qnap.com/en/security-advisory/qsa-25-37
Vendor Advisory