PT-2025-24305 · Unknown · Qsync Central

Coral

·

Published

2025-06-06

·

Updated

2025-06-10

·

CVE-2025-29892

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qsync Central versions prior to 4.5.0.6
Description An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, this issue could allow remote attackers who have gained user access to execute unauthorized code or commands.
Recommendations For versions prior to 4.5.0.6, update to Qsync Central version 4.5.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of Qsync Central to minimize the risk of exploitation.

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-06748
CVE-2025-29892

Affected Products

Qsync Central