CVE-2025-57707CWE-96

File Station 5

Low · published February 11, 2026

CVSS v4.0
1.1
EPSS
1%
Percentile
49.1
In the wild
Unconfirmed
What it is

An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to access restricted data / files.

We have already fixed the vulnerability in the following version:

File Station 5 5.5.6.5166 and later

The record
Technical detail
CVSS v4.0
1.1 · LOW
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
EPSS
0.00655 · 49.1th percentile
Weakness
CWE-96 · Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
Published
2026-02-11T12:17Z
EPSS history
Timeline
  • 11 FEB 12:17Z
    File Station 5
    cvelistv5