CVE-2025-57707

8.8

QNAP Systems Inc. · File Station 5

A static code injection vulnerability in QNAP File Station 5 allows an authenticated remote attacker to access restricted files or data.

Executive summary

A static code injection vulnerability in QNAP File Station 5, identified as CVE-2025-57707, poses a significant risk of unauthorized data access for authenticated users.

Vulnerability

This vulnerability involves improper neutralization of directives in statically saved code (CWE-96). An attacker who has already gained access to a user account can exploit this flaw to bypass restrictions and access sensitive files.

Business impact

The ability for an authenticated user to access restricted data threatens the confidentiality of stored information. While the CVSS score of 8.8 reflects high severity, the requirement for an existing user account limits the initial attack vector, though the impact remains substantial for organizations relying on QNAP devices for secure file storage.

Remediation

Immediate Action: Update QNAP File Station 5 to version 5.5.6.5166 or later to apply the necessary security patches.

Proactive Monitoring: Review system and access logs for unusual file access patterns or unauthorized attempts to navigate outside of defined user directories.

Compensating Controls: Ensure that user accounts are restricted to the minimum necessary permissions and implement network-level segmentation to prevent unauthorized lateral movement.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations using affected QNAP File Station 5 versions should prioritize the update to version 5.5.6.5166 immediately to remediate this vulnerability. Given the potential for unauthorized data access, maintaining strict account management and logging practices is essential until the patch is successfully deployed across all affected instances.

More QNAP Systems Inc. CVEs

Sources

Originally found and disclosed by Kutay Ergen, per the CVE Program record.