CVE-2025-57713 PUBLISHED

File Station 5

Assigner: qnap
Reserved: 18.08.2025 Published: 11.02.2026 Updated: 11.02.2026

A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information.

We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
CVSS Score: 1.3

Product Status

Vendor QNAP Systems Inc.
Product File Station 5
Versions Default: unaffected
  • affected from 5.5.x to 5.5.6.5166 (excl.)

Solutions

We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

Credits

  • Mohammad Abdullah - Infosec Researcher & Bugbounty hunter finder

References

Problem Types

  • CWE-1390 CWE

Impacts

  • CAPEC-115