A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: Download Station 5.10.0.305 ( 2025/09/16 ) and later Download Station 5.10.0.304 ( 2025/09/08 ) and later
2025-11-07T16:15:41.230
2025-11-17T15:39:47.067
Analyzed
CVSSv3.1: 5.4 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | qnap | download_station | 5.10.0.291 | Yes |
| Operating System | qnap | quts_hero | h5.2.1.2929 | No |
| Operating System | qnap | quts_hero | h5.2.1.2940 | No |
| Application | qnap | download_station | < 5.10.0.305 | Yes |
| Operating System | qnap | qts | 5.2.1.2930 | No |