CVE-2025-58465 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vu…
Low CVSS: 2.2

CVE-2025-58465

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data.

We have already fixed the vulnerability in the following versions:
Download Station 5.10.0.305 ( 2025/09/16 ) and later
Download Station 5.10.0.304 ( 2025/09/08 ) and later
Vendor
Qnap
Product
Download Station
CWE
CWE-79
Yayın Tarihi
2025-11-07 16:15:41
Güncelleme
2025-11-17 15:39:47
Source Identifier
security@qnapsecurity.com.tw
KEV Date Added
-

Kategoriler

Referanslar