CVE-2025-57707
An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to access restricted data / files. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later
Scoring
- Severity
- LOW
- CVSS base score
- 1.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
- EPSS probability
- 0.66%
- CWE
- CWE-96
- Published
- 2026-02-11
- Last modified
- 2026-03-13
Affected products
- QNAP Systems Inc. File Station 5
Weakness type
Related vulnerabilities
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2025-7825 — Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
- CVE-2025-36595 — Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of...
- CVE-2015-2079 — Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution...
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command....
- CVE-2024-13268 — Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
- CVE-2024-13267 — Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
- CVE-2024-13265 — Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029