« Back to list

Qnap

Qnap File Station: vulnerabilities and CVEs

Qnap File Station has 54 published vulnerabilities, 28 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs54
Last 12 months28
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-26241Low (1.3)0.56%—Jun 10, 2026
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…
CVE-2026-26240Low (1.3)0.56%—Jun 10, 2026
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the…
CVE-2026-26239Medium (6.3)0.52%—Jun 10, 2026
A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2026-24724Medium (6.2)0.34%—Jun 10, 2026
An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions. We have…
CVE-2026-24720Low (1.3)0.38%—Jun 10, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2026-22899Low (1.3)0.38%—Jun 10, 2026
A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2026-22894Low (1.3)0.57%—Feb 11, 2026
A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-66278Low (1.3)0.44%—Feb 11, 2026
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-62856Low (1.3)0.35%—Feb 11, 2026
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system…
CVE-2025-62855Low (1.3)0.36%—Feb 11, 2026
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system…
CVE-2025-62854Low (1.3)0.57%—Feb 11, 2026
An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)…
CVE-2025-62853Medium (5.2)0.64%—Feb 11, 2026
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-57713Low (1.3)0.54%—Feb 11, 2026
A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the…
CVE-2025-57707Low (1.1)0.70%—Feb 11, 2026
An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the…
CVE-2025-54169Medium (4.9)0.36%—Feb 11, 2026
An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the…
CVE-2025-54163Low (1.2)0.53%—Feb 11, 2026
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS)…
CVE-2025-54162Medium (4.8)0.46%—Feb 11, 2026
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system…
CVE-2025-54161Low (3.6)0.43%—Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-54155Low (3.6)0.43%—Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-57706Low (2.2)0.20%—Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application…
CVE-2025-53413Medium (4.9)0.46%—Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-53412Low (0.6)0.46%—Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-53411Low (1.2)0.48%—Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-53410Medium (4.9)0.46%—Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-53409Medium (4.9)0.46%—Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-53408Low (1.3)0.34%—Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-52865Low (1.3)0.34%—Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-47207Medium (5.3)0.34%—Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS)…
CVE-2025-29900High (7.1)0.46%—Aug 29, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-29899High (7.1)0.46%—Aug 29, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services14
  2. T1557 Adversary-in-the-Middle6
  3. T1499 Endpoint Denial of Service5
  4. T1499.004 Application or System Exploitation2
  5. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qnap