CVE-2025-58468
MEDIUMQnap Systems Inc. Notification Center < 1.10.0.3291 - CSRF
Title source: ruleDescription
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later
References (1)
Core 1
Core References
Scores
CVSS v4
5.1
EPSS
0.0018
EPSS Percentile
8.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (1)
QNAP Systems Inc./Notification Center
1.10.0 - 1.10.0.3291
Published
Jun 10, 2026
Tracked Since
Jun 10, 2026