CVE-2025-33035 Overview
CVE-2025-33035 is a path traversal vulnerability [CWE-22] affecting QNAP File Station 5. An authenticated remote attacker with a valid user account can traverse directories outside the intended file scope. Successful exploitation allows the attacker to read unexpected files and system data on the underlying NAS device.
QNAP addressed the issue in File Station 5 version 5.5.6.4847 and later. The vulnerability is tracked in QNAP Security Advisory QSA-25-16.
Critical Impact
Authenticated attackers can read arbitrary files accessible to the File Station process, exposing configuration data, credentials, and other sensitive content stored on the NAS.
Affected Products
- QNAP File Station 5 (versions prior to 5.5.6.4847)
- QNAP NAS devices running vulnerable File Station 5 builds
- Deployments exposing File Station 5 to remote authenticated users
Discovery Timeline
- 2025-06-06 - CVE-2025-33035 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-33035
Vulnerability Analysis
The vulnerability resides in File Station 5, QNAP's web-based file management application for QTS and QuTS hero NAS operating systems. File Station handles user requests to browse, upload, and download files stored on the appliance. The affected code paths fail to properly canonicalize or validate user-supplied file paths.
An attacker who holds any valid File Station user account can craft requests containing directory traversal sequences. These sequences escape the intended file scope and reach arbitrary locations on the NAS filesystem. The attacker gains read access to files that the File Station service can access, which may include system configuration, application data, and other users' files.
QNAP resolved the flaw in File Station 5 build 5.5.6.4847. Administrators should treat any NAS exposed to untrusted authenticated users as a priority for patching.
Root Cause
The root cause is improper limitation of a pathname to a restricted directory [CWE-22]. File Station 5 accepts path parameters from authenticated users and passes them to filesystem operations without sufficient normalization. Traversal tokens such as ../ are interpreted literally by the operating system, breaking out of the intended base directory.
Attack Vector
Exploitation requires network access to the File Station web interface and valid low-privilege credentials. No user interaction is needed once the attacker holds an account. The attacker submits HTTP requests to File Station endpoints with manipulated path parameters. The service resolves the traversal sequences and returns file contents outside the authorized directory tree.
No verified public proof-of-concept code is available. Refer to the QNAP Security Advisory QSA-25-16 for vendor-supplied technical detail.
Detection Methods for CVE-2025-33035
Indicators of Compromise
- HTTP requests to File Station endpoints containing ../, ..%2f, ..%5c, or double-encoded traversal sequences in path or filename parameters.
- Unexpected read access by the File Station process to files outside standard shared folders, including /etc/, application databases, or configuration files.
- File Station access logs showing directory listings or downloads for paths a given user account should not reach.
Detection Strategies
- Inspect web server and File Station logs for encoded and unencoded traversal patterns in request URIs and POST bodies.
- Baseline normal File Station usage per account and alert on requests that reference system paths or absolute filesystem locations.
- Correlate authentication events with file access telemetry to identify low-privilege accounts reading sensitive system files.
Monitoring Recommendations
- Forward QNAP QuLog Center and File Station audit logs to a centralized SIEM for retention and correlation.
- Alert on repeated 200-OK responses to requests containing traversal tokens after successful authentication.
- Monitor for anomalous outbound data transfers from NAS devices following File Station activity from a single account.
How to Mitigate CVE-2025-33035
Immediate Actions Required
- Upgrade File Station 5 to version 5.5.6.4847 or later through the QTS App Center on every affected NAS.
- Audit File Station user accounts and disable or rotate credentials for any account not actively required.
- Restrict File Station exposure to trusted networks and remove any direct internet accessibility where possible.
- Review File Station access logs for traversal patterns dating back to before the patch was applied.
Patch Information
QNAP has released a fixed build. Install File Station 5 version 5.5.6.4847 or later. Details and download guidance are provided in QNAP Security Advisory QSA-25-16. Reboot the NAS if required by the App Center after installation.
Workarounds
- Disable the File Station 5 application in the QTS App Center until the patched build can be installed.
- Place the NAS behind a VPN or firewall rule that limits File Station access to known administrative IP addresses.
- Enforce strong password policies and two-step verification on all NAS accounts to reduce the risk of credential-based access.
# Verify File Station 5 version on QTS via SSH
qpkg_cli --list | grep -i "File Station 5"
# Restrict File Station web port (default 8080) to a management subnet
iptables -A INPUT -p tcp --dport 8080 -s 10.10.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8080 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
