PT-2025-40588 · Qnap · Qsync Central

Coral

·

Published

2025-10-03

·

Updated

2025-10-04

·

CVE-2025-53595

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qsync Central versions prior to 5.0.0.2
Description An SQL injection issue exists in Qsync Central. A remote attacker who obtains a user account can potentially execute unauthorized code or commands. The vulnerability is exploitable through SQL injection.
Recommendations Update to Qsync Central version 5.0.0.2 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-16026
CVE-2025-53595

Affected Products

Qsync Central