AI description
CVE-2025-59384 is a path traversal vulnerability that affects Qfiling. Remote attackers can exploit this vulnerability to read the contents of unexpected files or system data. The vulnerability exists due to insufficient input validation of pathnames, which allows attackers to bypass intended restrictions. Qfiling version 3.13.1 and later contain the fix for this vulnerability.
- Description
- A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qfiling 3.13.1 and later
- Source
- security@qnapsecurity.com.tw
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- security@qnapsecurity.com.tw
- CWE-22
- Hype score
- Not currently trending
QNAP、Qfilingのパストラバーサル 脆弱性を修正(CVE-2025-59384) https://t.co/vZqjhU2YbS #セキュリティ対策Lab #セキュリティ #Security #サイバー攻撃
@securityLab_jp
7 Jan 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-59384 (CVSS 8.1): Qfiling A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following
@zoomeye_team
5 Jan 2026
4598 Impressions
19 Retweets
40 Likes
11 Bookmarks
0 Replies
0 Quotes
QNAPが深刻な脆弱性2件を修正。QfilingのパストラバーサルCVE-2025-59384とMARSのSQLインジェクションで、いずれもCVSSスコア8.1。その他複数製品でも脆弱性修正あり。 https://t.co/K1vymZVbX4
@__kokumoto
5 Jan 2026
512 Impressions
1 Retweet
2 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2025-59384 A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files o… https://t.co/6AdV43Lp6I
@CVEnew
2 Jan 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes