We have already fixed the vulnerability in the following versions:
Notification Center 2.1.0.3443 and later
Notification Center 1.9.2.3163 and later
Notification Center 3.0.0.3466 and later
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
We have already fixed the vulnerability in the following versions: Notification Center 2.1.0.3443 and later Notification Center 1.9.2.3163 and later Notification Center 3.0.0.3466 and later
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-40 |
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap notification Center |
|
| Vendors & Products |
Qnap
Qnap notification Center |
Fri, 07 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: Notification Center 2.1.0.3443 and later Notification Center 1.9.2.3163 and later Notification Center 3.0.0.3466 and later | |
| Title | Notification Center | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2025-11-07T15:57:14.662Z
Reserved: 2025-07-17T08:05:28.816Z
Link: CVE-2025-54167
Updated: 2025-11-07T15:49:26.917Z
Status : Awaiting Analysis
Published: 2025-11-07T16:15:40.100
Modified: 2025-11-12T16:20:22.257
Link: CVE-2025-54167
No data.
OpenCVE Enrichment
Updated: 2025-11-10T09:34:47Z