CVE-2025-58468

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:notification_center:*:*:*:*:*:*:*:*

History

05 Aug 2026, 13:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:qnap:notification_center:*:*:*:*:*:*:*:*
First Time Qnap notification Center
Qnap
References () https://www.qnap.com/en/security-advisory/qsa-26-13 - () https://www.qnap.com/en/security-advisory/qsa-26-13 - Vendor Advisory

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Se ha informado que una vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) afecta a Notification Center. Los atacantes remotos pueden entonces explotar la vulnerabilidad para obtener privilegios o secuestrar identidades de usuario. Ya hemos corregido la vulnerabilidad en la siguiente versión: Notification Center 1.10.0.3291 y posteriores

10 Jun 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 03:16

Updated : 2026-08-05 13:59


NVD link : CVE-2025-58468

Mitre link : CVE-2025-58468

CVE.ORG link : CVE-2025-58468


JSON object : View

Products Affected

qnap

  • notification_center
CWE
CWE-352

Cross-Site Request Forgery (CSRF)