CNNVD-202511-747 Information

CNNVD ID

CNNVD-202511-747

CVE-2025-58463

  • CNNVD Published: 2025-11-07

Description (Chinese)

QNAP Download Station是中国台湾威联通科技(QNAP)公司的一个基于网页的下载工具。 QNAP Download Station存在安全漏洞,该漏洞源于相对路径遍历,可能导致读取意外文件或系统数据。

Description (English)

QNAP Download State is a web-based downloading tool for QNAP. There is a security loophole in QNAP Download State, which originates from a relative path through which unexpected files or system data can be read.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

威联通科技

Published

2025-11-07

Last Modified

2026-02-24

References

https://www.qnap.com/en/security-advisory/qsa-25-37 https://access.redhat.com/security/cve/cve-2025-58463

Patch

https://www.qnap.com/en/security-advisory/qsa-25-37

Share on: