Improper Certificate Validation in File Station 5 by QNAP
CVE-2025-29883

8.3HIGH

Key Information:

Vendor

QNAP

Vendor
CVE Published:
6 June 2025

What is CVE-2025-29883?

An improper certificate validation vulnerability has been identified in QNAP's File Station 5, potentially allowing remote attackers who have gained user access to compromise the system's security. This flaw can be exploited if users are not operating on the updated versions. It is crucial for users to upgrade to File Station 5 version 5.5.6.4791 or later to mitigate risks and ensure system integrity.

Affected Version(s)

File Station 5 5.5.x < 5.5.6.4791

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

coral
.
CVE-2025-29883 : Improper Certificate Validation in File Station 5 by QNAP