Executive brief
A security vulnerability has been identified in QNAP File Station 5, a web-based tool used for managing files on QNAP storage devices. If an attacker obtains access to a standard user account, they can exploit this flaw to crash system processes or modify sensitive memory. This could lead to a total loss of system availability or unauthorized control over the storage device.
Technical details
A stack-based buffer overflow (CWE-121) exists in QNAP File Station 5. The vulnerability is reachable over the network and requires the attacker to have authenticated access with a standard user account (PR:L). By sending specially crafted input, an attacker can overflow a buffer on the stack to modify memory or crash processes, potentially leading to arbitrary code execution. The issue is resolved in File Station 5 version 5.5.6.5208 and later.
Affected products
- QNAP Systems, Inc. File Station 5 versions prior to 5.5.6.5208
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory