External Accessibility Vulnerability in File Station by QNAP
CVE-2024-48864

5.3MEDIUM

Key Information:

Vendor
QNAP
Vendor
CVE Published:
7 March 2025

Summary

A serious vulnerability has been identified in QNAP’s File Station, particularly affecting File Station 5. This vulnerability allows unauthorized remote attackers to access or manipulate files and directories, posing a significant threat to data integrity and confidentiality. It is crucial for users to upgrade to File Station 5 version 5.5.6.4741 or later to mitigate potential risks associated with this security flaw. Ensure your systems are updated to protect against unauthorized access.

Affected Version(s)

File Station 5 5.5.x < 5.5.6.4741

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pwn2Own 2024 - ExLuck of ANHTUD
.