CVE-2025-54154

MEDIUM WAF: Low
CVSS 6.8 Published: 2025-10-03
CWE-287

An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP Authenticator 1.3.1.1227 and later

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
qnapauthenticator1.3.0 - 1.3.1.1227

References

Back to CVE Database