CVE-2026-26240
file_station: Stack-based Buffer Overflow (CVE-2026-26240)
Beschreibung
Ein Bericht über eine Schwachstelle durch einen Pufferüberlauf wurde für File Station 5 veröffentlicht. Angreifer können diese Schwachstelle aus der Ferne ausnutzen, um den Speicher zu ändern oder Prozesse zum Absturz zu bringen. Wir haben die Schwachstelle in folgender Version behoben: File Station 5 5.5.6.5243 und später
Metriken
Weakness-Klassen (CWE)
CWE-121Variant
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Translated2026-07-23 09:10 UTC· nvd@nist.gov
- Translation: Title: File Station 5 de QNAP Systems, Description: Se ha reportado una vulnerabilidad de desbordamiento de búfer que afecta a File Station 5. Los atacantes remotos pueden entonces explotar la vulnerabilidad para modificar la memoria o bloquear procesos. Ya hemos corregido la vulnerabilidad en la siguiente versión: File Station 5 5.5.6.5243 y posteriores
- Initial Analysis2026-06-12 12:52 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- CPE Configuration: OR *cpe:2.3:a:qnap:file_station:*:*:*:*:*:*:*:* versions from (including) 5.5.6.4691 up to (excluding) 5.5.6.5243
- Reference Type: QNAP Systems, Inc.: https://www.qnap.com/en/security-advisory/qsa-26-32 Types: Broken Link
- New CVE Received2026-06-10 05:16 UTC· security@qnapsecurity.com.tw
- Description: A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later
- CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE: CWE-121
- Reference: https://www.qnap.com/en/security-advisory/qsa-26-32
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
qnap
file_station5.5.6.4691 – 5.5.6.5243