Externally-Controlled Format String Vulnerability in Qsync Central by QNAP
CVE-2025-22482
2.3LOW
What is CVE-2025-22482?
A vulnerability in Qsync Central allows remote attackers, possessing user access, to exploit an externally-controlled format string, potentially leading to unauthorized access to confidential information or the ability to modify memory. This issue has been mitigated in versions 4.5.0.6 and later.
Affected Version(s)
Qsync Central 4.5.x.x < 4.5.0.6 ( 2025/03/20 )