Cross-Site Scripting Vulnerability in QNAP Operating Systems
CVE-2025-22483

7.1HIGH

Key Information:

Vendor

QNAP

Vendor
CVE Published:
29 August 2025

What is CVE-2025-22483?

A cross-site scripting vulnerability has been discovered in multiple versions of QNAP operating systems. This flaw allows a remote attacker with access to an administrator account to exploit the system, potentially bypassing established security measures, leading to unauthorized access to sensitive application data. Prompt action is advised to mitigate the risks associated with this vulnerability. The issue has been addressed in License Center versions 1.8.51 and 1.9.51 and later.

Affected Version(s)

License Center 1.8.x < 1.8.51

License Center 1.9.x < 1.9.51

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Milan Solanki (LeoSecurity)
.