Security ID : QSA-25-38
Multiple Vulnerabilities in File Station 5
Release date : November 8, 2025
CVE identifier : CVE-2025-47207 | CVE-2025-53408 | CVE-2025-53409 | CVE-2025-53410 | CVE-2025-53411 | CVE-2025-53412 | CVE-2025-53413 | CVE-2025-52865 | CVE-2025-57706
Affected products: File Station 5 version 5.5.x
Severity
Moderate
Status
Resolved
Summary
Multiple vulnerabilities have been reported to affect File Station 5:
- CVE-2025-53410: Allocation of resources without limits or throttling vulnerability
If a remote attacker gains access to a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. - CVE-2025-53409, CVE-2025-53411, CVE-2025-53413: Allocation of resources without limits or throttling vulnerabilities
If a remote attacker gains access to an administrator account, they can then exploit the vulnerabilities to prevent other systems, applications, or processes from accessing the same type of resource. - CVE-2025-47207, CVE-2025-52865, CVE-2025-53408, CVE-2025-53412: NULL pointer dereference vulnerabilities
If a remote attacker gains access to a user account, they can then exploit the vulnerabilities to launch a denial-of-service (DoS) attack. - CVE-2025-57706: Cross-site scripting (XSS) vulnerability
If a remote attacker gains access to a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerabilities in the following version:
| Affected Product | Fixed Version |
| File Station 5 version 5.5.x | File Station 5 version 5.5.6.5018 and later |
Recommendation
To fix the vulnerabilities, we recommend updating File Station 5 to the latest version.
Updating File Station 5
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "File Station 5" and then press ENTER.
File Station 5 appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your File Station 5 is already up to date. - Click OK.
The system updates the application.
Attachment
- CVE-2025-53411.json
- CVE-2025-52865.json
- CVE-2025-53410.json
- CVE-2025-53408.json
- CVE-2025-53409.json
- CVE-2025-53412.json
- CVE-2025-53413.json
- CVE-2025-57706.json
- CVE-2025-47207.json
Acknowledgements: coral
Revision History:
V1.0 (November 8, 2025) - Published