An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.

We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.5018 and later
Advisories

No advisories yet.

Fixes

Solution

We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 15:30:00 +0000

Type Values Removed Values Added
Description An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later
Title File Station 5
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 4.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2025-11-07T15:56:12.638Z

Reserved: 2025-06-30T07:19:56.928Z

Link: CVE-2025-53409

cve-icon Vulnrichment

Updated: 2025-11-07T15:47:04.353Z

cve-icon NVD

Status : Received

Published: 2025-11-07T16:15:39.247

Modified: 2025-11-07T16:15:39.247

Link: CVE-2025-53409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.