A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later
History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Qnap Systems
Qnap Systems file Station 5
Vendors & Products Qnap Systems
Qnap Systems file Station 5

Wed, 11 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 12:45:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later
Title File Station 5
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 1.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published: 2026-02-11T12:15:55.297Z

Updated: 2026-02-11T16:50:14.744Z

Reserved: 2025-10-24T02:43:49.269Z

Link: CVE-2025-62856

cve-icon Vulnrichment

Updated: 2026-02-11T16:50:11.795Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T13:15:58.107

Modified: 2026-02-11T15:27:26.370

Link: CVE-2025-62856

cve-icon Redhat

No data.