Resource Exhaustion Vulnerability in QNAP File Station 5
CVE-2025-29890

7.1HIGH

Key Information:

Vendor

QNAP

Vendor
CVE Published:
29 August 2025

What is CVE-2025-29890?

A resource exhaustion vulnerability has been identified in QNAP's File Station 5. This issue enables a remote attacker with valid user credentials to exploit the system, potentially leading to service disruption by monopolizing shared resources. The flaw restricts other systems, applications, or processes from accessing the available resources, causing operational impairment. The vulnerability has been addressed in version 5.5.6.4907 and later.

Affected Version(s)

File Station 5 5.5.x < 5.5.6.4907

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

coral
.