CVE-2025-57713

7.5

QNAP · File Station 5

QNAP File Station 5 contains a weak authentication vulnerability that allows remote attackers to gain unauthorized access to sensitive information.

Executive summary

A weak authentication vulnerability in QNAP File Station 5 allows remote attackers to access sensitive information, necessitating an immediate update to the latest version.

Vulnerability

The vulnerability, classified as CWE-1390, involves a weak authentication mechanism that can be exploited by unauthenticated, remote attackers to retrieve sensitive data from the affected system.

Business impact

The ability for remote attackers to obtain sensitive information can lead to unauthorized data disclosure and potential exposure of proprietary or private files stored within the NAS environment. With a CVSS score of 7.5, this high severity flaw poses a significant risk to data confidentiality, as it bypasses standard access protections to expose internal assets.

Remediation

Immediate Action: Update QNAP File Station 5 to version 5.5.6.5166 or later to apply the vendor-provided security fix.

Proactive Monitoring: Review system access logs for anomalous patterns or unauthorized requests directed at the File Station service.

Compensating Controls: Ensure the QNAP device is not directly exposed to the public internet and utilize a VPN or restricted network access to manage the interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized access to sensitive data, administrators should prioritize updating File Station 5 to version 5.5.6.5166 immediately. Restricting management access to trusted networks remains a critical best practice to mitigate the risk of exploitation while the update is being deployed.

More QNAP CVEs

Sources

Originally found and disclosed by Mohammad Abdullah - Infosec Researcher & Bugbounty hunter, per the CVE Program record.