A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version:
License Center 1.9.56 and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-28 |
|
History
Wed, 10 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and later | |
| Title | License Center | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2026-06-10T03:02:44.924Z
Updated: 2026-06-10T03:02:44.924Z
Reserved: 2025-10-24T02:43:49.268Z
Link: CVE-2025-62851
No data.
Status : Received
Published: 2026-06-10T04:17:11.913
Modified: 2026-06-10T04:17:11.913
Link: CVE-2025-62851
No data.