Static Code Injection Vulnerability in QNAP File Station 5
CVE-2025-57707

1.1LOW

Key Information:

Vendor

QNAP

Vendor
CVE Published:
11 February 2026

What is CVE-2025-57707?

A significant security issue exists in QNAP's File Station 5, where static code is improperly neutralized, allowing remote attackers with user accounts to potentially exploit this vulnerability. This exploit could enable unauthorized access to restricted files and sensitive data. QNAP has responded to this threat, providing essential updates in File Station 5 version 5.5.6.5166 and later to remediate the issue effectively.

Affected Version(s)

File Station 5 5.5.x < 5.5.6.5166

References

CVSS V4

Score:
1.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kutay Ergen
.