CVE-2025-29885

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*

History

18 Jun 2025, 19:24

Type Values Removed Values Added
References () https://www.qnap.com/en/security-advisory/qsa-25-09 - () https://www.qnap.com/en/security-advisory/qsa-25-09 - Vendor Advisory
First Time Qnap file Station
Qnap
CPE cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

09 Jun 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Se ha informado de una vulnerabilidad de validación incorrecta de certificados que afecta a File Station 5. Si se explota, esta vulnerabilidad podría permitir que atacantes remotos con acceso de usuario comprometan la seguridad del sistema. Ya hemos corregido la vulnerabilidad en las siguientes versiones: File Station 5 5.5.6.4791 y posteriores.

06 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 16:15

Updated : 2025-06-18 19:24


NVD link : CVE-2025-29885

Mitre link : CVE-2025-29885

CVE.ORG link : CVE-2025-29885


JSON object : View

Products Affected

qnap

  • file_station
CWE
CWE-295

Improper Certificate Validation