VYPR
Unrated severityNVD Advisory· Published Nov 7, 2025· Updated Nov 7, 2025

Download Station

CVE-2025-58463

Description

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.

We have already fixed the vulnerability in the following versions: Download Station 5.10.0.305 ( 2025/09/16 ) and later Download Station 5.10.0.304 ( 2025/09/08 ) and later

Affected products

1
  • QNAP Systems Inc./Download Stationv5
    Range: 5.10.x

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.