CVE-2025-33035: File Station 5
Published Jun 6, 2025
·Updated
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later
Affected Software
2 affected components
Synology File Station 5<5.5.6.4847
QNAP File Station>=5.5.6.4691<5.5.6.4847
Remediation
Information
We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.4847 and later
Event History
Jun 6, 2025
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33035?
CVE-2025-33035 is classified as a moderate severity path traversal vulnerability.
2
How do I fix CVE-2025-33035?
To fix CVE-2025-33035, update your Synology File Station 5 to version 5.5.6.4847 or later.
3
What systems are affected by CVE-2025-33035?
CVE-2025-33035 affects the Synology File Station 5 software.
4
What can an attacker do with CVE-2025-33035?
An attacker with a user account can exploit CVE-2025-33035 to read unexpected files or system data.
5
Is a patch available for CVE-2025-33035?
Yes, a patch for CVE-2025-33035 is available in version 5.5.6.4847 of Synology File Station 5.