A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later
References
| Link | Resource |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-37 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
History
No history.
Information
Published : 2025-11-07 16:15
Updated : 2025-11-17 15:40
NVD link : CVE-2025-58463
Mitre link : CVE-2025-58463
CVE.ORG link : CVE-2025-58463
JSON object : View
Products Affected
qnap
- quts_hero
- qts
- download_station
CWE
CWE-23
Relative Path Traversal
