Uncontrolled Resource Consumption in Qsync Central by QNAP
CVE-2025-29898

6MEDIUM

Key Information:

Vendor

QNAP

Vendor
CVE Published:
29 August 2025

What is CVE-2025-29898?

An uncontrolled resource consumption vulnerability in Qsync Central permits remote attackers with user accounts to exploit the system, potentially leading to denial-of-service (DoS) attacks. This allows malicious actors to overwhelm the resources of the server, causing disruptions in service and impacting overall functionality. The vulnerability has been rectified in version 4.5.0.7 and subsequent releases.

Affected Version(s)

Qsync Central 4.5.x.x < 4.5.0.7 ( 2025/04/23 )

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Searat and izut
.