A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later
References
| Link | Resource |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-37 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
History
17 Nov 2025, 15:40
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:qnap:quts_hero:h5.2.1.2940:build_20241105:*:*:*:*:*:* cpe:2.3:a:qnap:download_station:*:*:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:h5.2.1.2929:build_20241025:*:*:*:*:*:* cpe:2.3:o:qnap:qts:5.2.1.2930:build_20241025:*:*:*:*:*:* cpe:2.3:a:qnap:download_station:5.10.0.291:*:*:*:*:*:*:* |
|
| First Time |
Qnap
Qnap download Station Qnap quts Hero Qnap qts |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
| References | () https://www.qnap.com/en/security-advisory/qsa-25-37 - Vendor Advisory |
07 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-07 16:15
Updated : 2025-11-17 15:40
NVD link : CVE-2025-58463
Mitre link : CVE-2025-58463
CVE.ORG link : CVE-2025-58463
JSON object : View
Products Affected
qnap
- download_station
- qts
- quts_hero
CWE
CWE-23
Relative Path Traversal
