Junglewise Threat Intelligence

CVE-2026-26241: QNAP File Station 5 buffer overflow

CVE-2026-26241 · Severity: info · CVSS 5.3 · Published 2026-06-10

Technologies: QNAP Systems, Inc. File Station 5. Vendors: QNAP Systems, Inc..

Executive brief

A security vulnerability has been identified in QNAP File Station 5, a web-based tool used for managing files on QNAP storage devices. An attacker could exploit this flaw to cause the application to crash or to modify its internal memory. This could lead to service disruptions or unauthorized changes to how the system handles data.

Technical details

A stack-based buffer overflow (CWE-121) exists in QNAP File Station 5. The vulnerability can be triggered by a remote attacker, though the CVSS vector suggests some level of user interaction (UI:P) may be required. Successful exploitation allows the attacker to modify memory contents or crash application processes, potentially leading to arbitrary code execution or a denial of service. The issue is resolved in File Station 5 version 5.5.6.5243 and later.

Affected products

  • QNAP Systems, Inc. File Station 5 versions prior to 5.5.6.5243

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats