Executive brief
QNAP File Station 5, a web-based tool for managing files on QNAP NAS devices, is affected by a security vulnerability. Remote attackers can exploit this flaw to crash the application or modify its memory, potentially disrupting file management operations. Users should update to the latest version to ensure the stability and security of their storage systems.
Technical details
A stack-based buffer overflow (CWE-121) exists in QNAP File Station 5. The vulnerability can be triggered by a remote attacker, though the CVSS vector indicates that some level of user interaction (UI:P) is required. Successful exploitation allows the attacker to modify memory or crash processes, leading to a denial-of-service condition. The issue is resolved in File Station 5 version 5.5.6.5243 and later.
Affected products
- QNAP Systems, Inc. File Station 5 versions prior to 5.5.6.5243
Timeline
- 2026-06-10: advisory: QNAP published security advisory QSA-26-32
- 2026-06-10: disclosed: CVE-2026-26240 published to NVD