Format String Vulnerability in Qsync Central by QNAP
CVE-2025-30269
0.6LOW
What is CVE-2025-30269?
A format string vulnerability has been identified in Qsync Central, which may allow remote attackers with user accounts to manipulate memory and access sensitive data. This vulnerability arises due to improper handling of user-controlled input, enabling the exploitation of format string directives. Users are urged to update to version 5.0.0.4 or later, released on January 20, 2026, to mitigate this risk. For more details, refer to the official security advisory.
Affected Version(s)
Qsync Central 5.0.x.x < 5.0.0.4 ( 2026/01/20 )