Qnap
Qnap File Station: vulnerabilidades y CVE
Qnap File Station tiene 54 vulnerabilidades publicadas, 28 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE54
Últimos 12 meses28
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-26241 | Baja (1.3) | 0.56% | — | 10 jun 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the… |
| CVE-2026-26240 | Baja (1.3) | 0.56% | — | 10 jun 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the… |
| CVE-2026-26239 | Media (6.3) | 0.52% | — | 10 jun 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2026-24724 | Media (6.2) | 0.34% | — | 10 jun 2026 | An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have… |
| CVE-2026-24720 | Baja (1.3) | 0.38% | — | 10 jun 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2026-22899 | Baja (1.3) | 0.38% | — | 10 jun 2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2026-22894 | Baja (1.3) | 0.57% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-66278 | Baja (1.3) | 0.44% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-62856 | Baja (1.3) | 0.35% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system… |
| CVE-2025-62855 | Baja (1.3) | 0.36% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system… |
| CVE-2025-62854 | Baja (1.3) | 0.57% | — | 11 feb 2026 | An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)… |
| CVE-2025-62853 | Media (5.2) | 0.64% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-57713 | Baja (1.3) | 0.54% | — | 11 feb 2026 | A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the… |
| CVE-2025-57707 | Baja (1.1) | 0.70% | — | 11 feb 2026 | An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the… |
| CVE-2025-54169 | Media (4.9) | 0.36% | — | 11 feb 2026 | An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the… |
| CVE-2025-54163 | Baja (1.2) | 0.53% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS)… |
| CVE-2025-54162 | Media (4.8) | 0.46% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system… |
| CVE-2025-54161 | Baja (3.6) | 0.43% | — | 11 feb 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-54155 | Baja (3.6) | 0.43% | — | 11 feb 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-57706 | Baja (2.2) | 0.20% | — | 7 nov 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application… |
| CVE-2025-53413 | Media (4.9) | 0.46% | — | 7 nov 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-53412 | Baja (0.6) | 0.46% | — | 7 nov 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-53411 | Baja (1.2) | 0.48% | — | 7 nov 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-53410 | Media (4.9) | 0.46% | — | 7 nov 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-53409 | Media (4.9) | 0.46% | — | 7 nov 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-53408 | Baja (1.3) | 0.34% | — | 7 nov 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-52865 | Baja (1.3) | 0.34% | — | 7 nov 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-47207 | Media (5.3) | 0.34% | — | 7 nov 2025 | A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)… |
| CVE-2025-29900 | Alta (7.1) | 0.46% | — | 29 ago 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-29899 | Alta (7.1) | 0.46% | — | 29 ago 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.