Impact
An out-of-bounds write flaw exists in QNAP File Station 5 that can be triggered by a remote attacker with a valid user account. The flaw allows modification of memory or termination of the File Station process, as identified by CWE‑121. The description does not state that the vulnerability leads to arbitrary code execution.
Affected Systems
QNAP Systems Inc. File Station 5, all releases prior to version 5.5.6.5208. Versions 5.5.6.5208 and later contain the vendor-provided fix.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity issue, but EPSS score of < 1% indicates a low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is authenticated remote, requiring a user account, and the exploitation would involve sending crafted traffic to trigger the buffer overflow.
OpenCVE Enrichment