CVE-2025-62856: File Station 5
A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62856?
CVE-2025-62856 is considered a high severity vulnerability that allows local attackers with administrative access to exploit path traversal.
How do I fix CVE-2025-62856?
To fix CVE-2025-62856, update Synology File Station 5 to version 5.5.6.5190 or higher, or QNAP File Station to between versions 5.5.6.4691 and 5.5.6.5190 as applicable.
What type of vulnerability is CVE-2025-62856?
CVE-2025-62856 is a path traversal vulnerability affecting File Station 5 software.
Who is affected by CVE-2025-62856?
CVE-2025-62856 affects users of Synology File Station 5 and QNAP File Station versions within the specified ranges.
What could an attacker potentially access through CVE-2025-62856?
An attacker exploiting CVE-2025-62856 could access unexpected files or system data due to the path traversal flaw.