« Volver al listado

Qnap

Qnap File Station: vulnerabilidades y CVE

Qnap File Station tiene 54 vulnerabilidades publicadas, 28 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE54
Últimos 12 meses28
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-26241Baja (1.3)0.56%—10 jun 2026
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…
CVE-2026-26240Baja (1.3)0.56%—10 jun 2026
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…
CVE-2026-26239Media (6.3)0.52%—10 jun 2026
A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2026-24724Media (6.2)0.34%—10 jun 2026
An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have…
CVE-2026-24720Baja (1.3)0.38%—10 jun 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2026-22899Baja (1.3)0.38%—10 jun 2026
A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2026-22894Baja (1.3)0.57%—11 feb 2026
A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-66278Baja (1.3)0.44%—11 feb 2026
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-62856Baja (1.3)0.35%—11 feb 2026
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system…
CVE-2025-62855Baja (1.3)0.36%—11 feb 2026
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system…
CVE-2025-62854Baja (1.3)0.57%—11 feb 2026
An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)…
CVE-2025-62853Media (5.2)0.64%—11 feb 2026
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-57713Baja (1.3)0.54%—11 feb 2026
A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the…
CVE-2025-57707Baja (1.1)0.70%—11 feb 2026
An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the…
CVE-2025-54169Media (4.9)0.36%—11 feb 2026
An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the…
CVE-2025-54163Baja (1.2)0.53%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS)…
CVE-2025-54162Media (4.8)0.46%—11 feb 2026
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system…
CVE-2025-54161Baja (3.6)0.43%—11 feb 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-54155Baja (3.6)0.43%—11 feb 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-57706Baja (2.2)0.20%—7 nov 2025
A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application…
CVE-2025-53413Media (4.9)0.46%—7 nov 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-53412Baja (0.6)0.46%—7 nov 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-53411Baja (1.2)0.48%—7 nov 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-53410Media (4.9)0.46%—7 nov 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-53409Media (4.9)0.46%—7 nov 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-53408Baja (1.3)0.34%—7 nov 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-52865Baja (1.3)0.34%—7 nov 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-47207Media (5.3)0.34%—7 nov 2025
A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)…
CVE-2025-29900Alta (7.1)0.46%—29 ago 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-29899Alta (7.1)0.46%—29 ago 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services14
  2. T1557 Adversary-in-the-Middle6
  3. T1499 Endpoint Denial of Service5
  4. T1499.004 Application or System Exploitation2
  5. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qnap