Executive brief
QNAP File Station is a web-based tool used to manage files on QNAP storage devices. A vulnerability has been identified where an authorized user can consume excessive system resources, potentially leading to a denial-of-service. This could prevent other users or critical system processes from accessing the storage device, impacting business operations and data availability.
Technical details
An allocation of resources without limits or throttling vulnerability (CWE-770) exists in QNAP File Station 6. The flaw allows a remote attacker with valid user credentials to exhaust system resources, such as memory or CPU, by making specific requests that are not properly throttled. Successful exploitation can lead to a denial-of-service (DoS) condition, preventing other applications or processes from accessing the same resource types. The issue is addressed in File Station 5 version 5.5.6.5243 and later.
Affected products
- QNAP File Station 6 Versions prior to 5.5.6.5243 (File Station 5 branch)
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory