CVE-2025-29871
BaseFortify
Publication date: 2025-06-06
Last updated on: 2025-06-18
Assigner: QNAP Systems, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qnap | file_station | From 5.5.6.4691 (inc) to 5.5.6.4847 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, update File Station 5 to version 5.5.6.4847 or later. You can do this by logging into QTS or QuTS hero as an administrator, accessing the App Center, searching for "File Station 5," and applying the update if available. [1]
Can you explain this vulnerability to me?
This vulnerability is an out-of-bounds read in File Station 5 that can be exploited by a local attacker who already has an administrator account. By exploiting this flaw, the attacker can access secret data that should otherwise be protected.
How can this vulnerability impact me? :
If exploited, this vulnerability allows an attacker with administrator access to obtain secret data from the system, potentially leading to unauthorized disclosure of sensitive information.