Path Traversal Vulnerability in QNAP File Station Software
CVE-2025-33035
7.2HIGH
What is CVE-2025-33035?
A path traversal vulnerability in QNAP File Station 5 allows remote attackers with valid user accounts to gain unauthorized access to sensitive files and system data. This flaw can be exploited to read files outside of the intended directories, compromising the integrity and confidentiality of the system. Users are urged to update to File Station 5 version 5.5.6.4847 or later to mitigate the risk associated with this vulnerability.
Affected Version(s)
File Station 5 5.5.x < 5.5.6.4847