PT-2025-40553 · Qnap · Qsync Central

Coral

·

Published

2025-10-03

·

Updated

2025-10-08

·

CVE-2025-44012

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Qsync Central versions prior to 5.0.0.2
Description A flaw exists in Qsync Central that allows a remote attacker, having obtained a user account, to exhaust resources and potentially prevent other systems, applications, or processes from accessing those resources. The issue stems from a lack of limits or throttling on resource allocation.
Recommendations Update to Qsync Central version 5.0.0.2 or later.

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-16024
CVE-2025-44012

Affected Products

Qsync Central