Resource Allocation Flaw in QNAP File Station by QNAP
CVE-2025-29899

7.1HIGH

Key Information:

Vendor

QNAP

Vendor
CVE Published:
29 August 2025

What is CVE-2025-29899?

A vulnerability has been identified in QNAP's File Station 5 that allows for unregulated resource allocation, potentially affecting system performance. If a remote attacker successfully obtains a user account, they can leverage this weakness to monopolize system resources, thereby preventing legitimate users from accessing essential services. This vulnerability highlights the importance of robust user account management and resource usage controls to maintain system integrity. The issue has been addressed in version 5.5.6.4907 and later.

Affected Version(s)

File Station 5 5.5.x < 5.5.6.4907

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

coral
.