CVE-2025-54155
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the s…
Ransomware groups specifically target backup systems to prevent recovery. Update immediately, then verify that at least one backup copy is offline or immutable (cloud with object lock, or air-gapped media). If your only backup is on a NAS exposed to the network, you have no ransomware recovery option.
NAS devices with internet-facing QuickConnect, DDNS, or direct port-forwarding are frequent ransomware targets. If remote access to the NAS is not essential, disable it. Use VPN to access NAS remotely instead.
SMB Attack Probability Score weights: EPSS exploit likelihood (35%), CISA KEV active exploitation (25%), SMB stack prevalence (20%), exploit maturity (10%), CVSS network vector complexity (10%). Impact scenarios are derived from software category and historical SMB incident patterns. Scores recompute daily.