VYPR

File Station

by Qnap

CVEs (48)

  • CVE-2025-33035MedJun 6, 2025
    risk 0.42cvss 6.5epss 0.00

    A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following…

  • CVE-2018-19942MedApr 16, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 build…

  • CVE-2020-2496MedDec 10, 2020
    risk 0.40cvss 6.1epss 0.01

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS…

  • CVE-2020-2495MedDec 10, 2020
    risk 0.40cvss 6.1epss 0.01

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS…

  • CVE-2020-2504MedDec 24, 2020
    risk 0.38cvss 5.8epss 0.01

    If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

  • CVE-2025-29871MedJun 6, 2025
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: File Station 5…

  • CVE-2025-57706MedNov 7, 2025
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the…

  • CVE-2025-53411MedNov 7, 2025
    risk 0.32cvss 4.9epss 0.00

    An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the…

Page 3 of 3