CVE-2026-24720
published 2026-06-10CVE-2026-24720: An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.28%
20.0th percentile
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.5243 and later
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | file_station | >= 5.5.6.4691 < 5.5.6.5243 | 5.5.6.5243 |
| qnap_systems_inc | file_station_5 | >= 5.5.0 < 5.5.6.5243 | 5.5.6.5243 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
QNAP File Station 5 5.5.6.5243 User Account allocation of resources (qsa-26-26 / EUVD-2026-35974)
vuldb·2026-06-15·CVSS 6.5
CVE-2026-24720 [MEDIUM] QNAP File Station 5 5.5.6.5243 User Account allocation of resources (qsa-26-26 / EUVD-2026-35974)
A vulnerability, which was classified as problematic, was found in QNAP File Station 5 5.5.6.5243. This affects an unknown part of the component User Account Handler. Such manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-24720. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6.
ghsa_unreviewed·2026-06-10
CVE-2026-24720 [MEDIUM] CWE-770 An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6.
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.5243 and later
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-10
Published