A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later
References
| Link | Resource |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-37 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
History
17 Nov 2025, 15:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.qnap.com/en/security-advisory/qsa-25-37 - Vendor Advisory | |
| First Time |
Qnap
Qnap quts Hero Qnap download Station Qnap qts |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
| CPE | cpe:2.3:o:qnap:qts:5.2.1.2930:build_20241025:*:*:*:*:*:* cpe:2.3:a:qnap:download_station:*:*:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:h5.2.1.2929:build_20241025:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:h5.2.1.2940:build_20241105:*:*:*:*:*:* cpe:2.3:a:qnap:download_station:5.10.0.291:*:*:*:*:*:*:* |
07 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-07 16:15
Updated : 2025-11-17 15:40
NVD link : CVE-2025-58463
Mitre link : CVE-2025-58463
CVE.ORG link : CVE-2025-58463
JSON object : View
Products Affected
qnap
- quts_hero
- qts
- download_station
CWE
CWE-23
Relative Path Traversal
