Executive brief
A security vulnerability has been identified in QNAP File Station 5, a web-based tool used for managing files on QNAP storage devices. An attacker could exploit this flaw to cause the application to crash or to modify its internal memory. This could lead to service disruptions or unauthorized changes to how the system handles data.
Technical details
A stack-based buffer overflow (CWE-121) exists in QNAP File Station 5. The vulnerability can be triggered by a remote attacker, though the CVSS vector suggests some level of user interaction (UI:P) may be required. Successful exploitation allows the attacker to modify memory contents or crash application processes, potentially leading to arbitrary code execution or a denial of service. The issue is resolved in File Station 5 version 5.5.6.5243 and later.
Affected products
- QNAP Systems, Inc. File Station 5 versions prior to 5.5.6.5243
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory