QNAP File Station 5 NULL Pointer Dereference Vulnerability Leading to Denial-of-Service

Vulnerability

A NULL pointer dereference vulnerability has been identified in QNAP File Station 5, specifically in version 5.5.x. This vulnerability allows remote attackers with user account access to exploit the issue, potentially leading to a denial-of-service (DoS) condition.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition, causing the application to become unresponsive or unavailable.

Remediation

Users are advised to update QNAP File Station 5 to version 5.5.6.4933 or later. Instructions for updating can be found in the QNAP App Center.

Added: Aug 26, 2025, 10:17 AM
Updated: Aug 26, 2025, 10:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.