CVE-2025-29883

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*

History

18 Jun 2025, 17:32

Type Values Removed Values Added
References () https://www.qnap.com/en/security-advisory/qsa-25-09 - () https://www.qnap.com/en/security-advisory/qsa-25-09 - Vendor Advisory
CPE cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Qnap file Station
Qnap

09 Jun 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Se ha informado de una vulnerabilidad de validación incorrecta de certificados que afecta a File Station 5. Si se explota, esta vulnerabilidad podría permitir que atacantes remotos con acceso de usuario comprometan la seguridad del sistema. Ya hemos corregido la vulnerabilidad en las siguientes versiones: File Station 5 5.5.6.4791 y posteriores.

06 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 16:15

Updated : 2025-06-18 17:32


NVD link : CVE-2025-29883

Mitre link : CVE-2025-29883

CVE.ORG link : CVE-2025-29883


JSON object : View

Products Affected

qnap

  • file_station
CWE
CWE-295

Improper Certificate Validation