Medium severity6.5NVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026
CVE-2026-22899
CVE-2026-22899
Description
A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later
Affected products
2cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*range: >=5.5.6.4691,<5.5.6.5208
- (no CPE)range: 6
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-26-19nvdBroken Link
News mentions
1- QNAP Patches Multiple Injection Vulnerabilities Leads to Arbitrary Command ExecutionCyber Security News · Jun 22, 2026