QNAP File Station 5 Resource Allocation Vulnerability Allowing Denial-of-Service

Vulnerability

A vulnerability has been identified in QNAP File Station 5, specifically in versions 5.5.x, that allows for resource allocation without limits or throttling. This issue can be exploited by remote attackers who gain access to an administrator account, enabling them to disrupt resource availability for other systems, applications, or processes. As a result, the vulnerability can be used to launch a denial-of-service attack.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, where affected resources become unavailable to users or applications.

Remediation

Users are advised to update QNAP File Station 5 to version 5.5.6.5018 or later. Instructions for updating the application are available on the QNAP website.

Added: Nov 7, 2025, 4:29 PM
Updated: Nov 7, 2025, 4:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.8
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.