Medium severity6.5NVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026
CVE-2026-24720
CVE-2026-24720
Description
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later
Affected products
2cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:*range: >=5.5.6.4691,<5.5.6.5243
- (no CPE)
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-26-26nvdBroken Link
News mentions
1- QNAP Patches Multiple Injection Vulnerabilities Leads to Arbitrary Command ExecutionCyber Security News · Jun 22, 2026