CVE-2025-22486
BaseFortify
Publication date: 2025-06-06
Last updated on: 2025-06-18
Assigner: QNAP Systems, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qnap | file_station | From 5.5.6.4691 (inc) to 5.5.6.4791 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper certificate validation issue in File Station 5. It means that the software does not correctly verify security certificates, which could allow remote attackers who already have user access to compromise the security of the system.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow remote attackers with user access to compromise the security of your system, potentially leading to unauthorized actions or data exposure.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, immediately update File Station 5 to version 5.5.6.4791 or later, where the vulnerability has been fixed. Additionally, restrict user access to trusted users only to reduce the risk of exploitation.