CVE-2025-22483: License Center
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22483?
CVE-2025-22483 is classified as a high-severity vulnerability due to its potential to allow remote attackers to exploit systems.
How do I fix CVE-2025-22483?
To fix CVE-2025-22483, update the QNAP License Center to a version greater than 1.9.51.
What systems are affected by CVE-2025-22483?
CVE-2025-22483 affects several versions of the QNAP License Center up to 1.9.51.
Can CVE-2025-22483 lead to data exposure?
Yes, if exploited, CVE-2025-22483 can allow attackers to read application data.
Is authentication required to exploit CVE-2025-22483?
Yes, an attacker needs administrator access to exploit CVE-2025-22483.