Improper Certificate Validation in File Station by QNAP
CVE-2025-29884

8.3HIGH

Key Information:

Vendor

QNAP

Vendor
CVE Published:
6 June 2025

What is CVE-2025-29884?

An improper certificate validation vulnerability has been identified in File Station 5 by QNAP, potentially allowing remote attackers with user access to compromise system security. If left unaddressed, this flaw could enable unauthorized modifications or access to sensitive information, making it crucial for users to upgrade to versions 5.5.6.4791 and later to ensure their systems are secure.

Affected Version(s)

File Station 5 5.5.x < 5.5.6.4791

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

coral
.
CVE-2025-29884 : Improper Certificate Validation in File Station by QNAP