QNAP Download Station Relative Path Traversal Vulnerability

Vulnerability

A relative path traversal vulnerability exists in QNAP Download Station versions 5.10.x. If a remote attacker gains access to an administrator account, they can exploit this vulnerability to read unintended files or system data.

Impact

Exploitation allows for unauthorized reading of files or system data, potentially leading to further attacks or information disclosure.

Remediation

Users can update Download Station to version 5.10.0.305 (for QTS 5.2.1) or version 5.10.0.304 (for QuTS hero h5.2.1). Instructions for updating Download Station are available on the QNAP website.

Added: Nov 7, 2025, 4:25 PM
Updated: Nov 7, 2025, 4:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
4.8
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.