PT-2025-40589 · Qnap · Qsync Central

Coral

·

Published

2025-10-03

·

Updated

2025-10-04

·

CVE-2025-54153

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qsync Central versions prior to 5.0.0.2
Description An SQL injection issue exists in Qsync Central. A remote attacker who obtains a user account can potentially execute unauthorized code or commands. The vulnerability allows for the execution of unauthorized code or commands.
Recommendations Update to Qsync Central version 5.0.0.2 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-16023
CVE-2025-54153

Affected Products

Qsync Central