CVE-2025-57707: File Station 5
An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to access restricted data / files.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57707?
CVE-2025-57707 is considered a critical vulnerability due to the potential for unauthorized access to restricted data.
How do I fix CVE-2025-57707?
To remediate CVE-2025-57707, update your Synology or QNAP File Station to the latest available version provided by the vendor.
Who is affected by CVE-2025-57707?
CVE-2025-57707 affects users of Synology File Station 5 versions prior to 5.5.6.5166 and QNAP File Station versions between 5.5.6.4691 and 5.5.6.5190.
Can an attacker exploit CVE-2025-57707 without a user account?
No, an attacker needs to gain access to a user account to exploit CVE-2025-57707 and access restricted files.
What type of vulnerability is CVE-2025-57707?
CVE-2025-57707 is classified as a static code injection vulnerability, which allows for improper neutralization of directives.