CVE-2025-54155 PUBLISHED

File Station 5

Assigner: qnap
Reserved: 17.07.2025 Published: 11.02.2026 Updated: 11.02.2026

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.

We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U
CVSS Score: 3.6

Product Status

Vendor QNAP Systems Inc.
Product File Station 5
Versions Default: unaffected
  • affected from 5.5.x to 5.5.6.5018 (excl.)

Solutions

We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later

Credits

  • coral finder

References

Problem Types

  • CWE-770 CWE

Impacts

  • CAPEC-131