Home

Description

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later

PUBLISHED Reserved 2025-09-03 | Published 2026-06-10 | Updated 2026-06-10 | Assigner qnap




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-352

Product status

Default status
unaffected

1.10.0 (custom) before 1.10.0.3291
affected

Credits

Tim Coen finder

References

www.qnap.com/en/security-advisory/qsa-26-13

cve.org (CVE-2025-58468)

nvd.nist.gov (CVE-2025-58468)

Download JSON