Impact
A buffer overflow flaw exists in QNAP File Station 5 that allows attackers to corrupt application memory or cause a crash. The vulnerability is identified as CWE-121, a classic buffer overflow scenario. Remote attackers can modify memory or crash processes.
Affected Systems
The vulnerability affects QNAP Systems Inc.’s File Station 5, specifically versions prior to 5.5.6.5243. Any device running a lower version is susceptible. No other products are listed as impacted.
Risk and Exploitability
The CVSS score of 1.3 indicates low severity, and the EPSS score is <1%, suggesting a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been widely observed in the wild. The exploit appears to be remote; attackers would need network access to the File Station interface to trigger the buffer overflow.
OpenCVE Enrichment