CVE-2025-62851

MEDIUM

Qnap Systems Inc. License Center < 1.9.56 - Path Traversal

Title source: rule
STIX 2.1

Description

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and later

Scores

CVSS v3 4.4
EPSS 0.0025
EPSS Percentile 15.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
qnap/license_center 1.9.36 - 1.9.56
QNAP Systems Inc./License Center 1.9.0 - 1.9.56
Published Jun 10, 2026
Tracked Since Jun 10, 2026