CVE-2025-58468

MEDIUM

Qnap Systems Inc. Notification Center < 1.10.0.3291 - CSRF

Title source: rule
STIX 2.1

Description

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later

References (1)

Core 1

Scores

CVSS v4 5.1
EPSS 0.0018
EPSS Percentile 8.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
QNAP Systems Inc./Notification Center 1.10.0 - 1.10.0.3291
Published Jun 10, 2026
Tracked Since Jun 10, 2026