Qnap
Qnap File Station: vulnerabilities and CVEs
Qnap File Station has 54 published vulnerabilities, 28 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs54
Last 12 months28
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26241 | Low (1.3) | 0.56% | — | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the… |
| CVE-2026-26240 | Low (1.3) | 0.56% | — | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the… |
| CVE-2026-26239 | Medium (6.3) | 0.52% | — | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2026-24724 | Medium (6.2) | 0.34% | — | Jun 10, 2026 | An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have… |
| CVE-2026-24720 | Low (1.3) | 0.38% | — | Jun 10, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2026-22899 | Low (1.3) | 0.38% | — | Jun 10, 2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2026-22894 | Low (1.3) | 0.57% | — | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-66278 | Low (1.3) | 0.44% | — | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-62856 | Low (1.3) | 0.35% | — | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system… |
| CVE-2025-62855 | Low (1.3) | 0.36% | — | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system… |
| CVE-2025-62854 | Low (1.3) | 0.57% | — | Feb 11, 2026 | An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)… |
| CVE-2025-62853 | Medium (5.2) | 0.64% | — | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-57713 | Low (1.3) | 0.54% | — | Feb 11, 2026 | A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the… |
| CVE-2025-57707 | Low (1.1) | 0.70% | — | Feb 11, 2026 | An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the… |
| CVE-2025-54169 | Medium (4.9) | 0.36% | — | Feb 11, 2026 | An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the… |
| CVE-2025-54163 | Low (1.2) | 0.53% | — | Feb 11, 2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS)… |
| CVE-2025-54162 | Medium (4.8) | 0.46% | — | Feb 11, 2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system… |
| CVE-2025-54161 | Low (3.6) | 0.43% | — | Feb 11, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-54155 | Low (3.6) | 0.43% | — | Feb 11, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-57706 | Low (2.2) | 0.20% | — | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application… |
| CVE-2025-53413 | Medium (4.9) | 0.46% | — | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-53412 | Low (0.6) | 0.46% | — | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-53411 | Low (1.2) | 0.48% | — | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-53410 | Medium (4.9) | 0.46% | — | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-53409 | Medium (4.9) | 0.46% | — | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-53408 | Low (1.3) | 0.34% | — | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-52865 | Low (1.3) | 0.34% | — | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-47207 | Medium (5.3) | 0.34% | — | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)… |
| CVE-2025-29900 | High (7.1) | 0.46% | — | Aug 29, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-29899 | High (7.1) | 0.46% | — | Aug 29, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.