A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities.
We have already fixed the vulnerability in the following version:
Notification Center 1.10.0.3291 and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-13 |
|
History
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems notification Center |
|
| Vendors & Products |
Qnap Systems
Qnap Systems notification Center |
Wed, 10 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later | |
| Title | Notification Center | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2026-06-10T01:38:27.401Z
Updated: 2026-06-10T01:38:27.401Z
Reserved: 2025-09-03T00:59:25.448Z
Link: CVE-2025-58468
No data.
Status : Received
Published: 2026-06-10T03:16:24.377
Modified: 2026-06-10T03:16:24.377
Link: CVE-2025-58468
No data.