Resource Management Vulnerability in Qsync Central by QNAP
CVE-2025-33040

7.1HIGH

Key Information:

Vendor

QNAP

Vendor
CVE Published:
3 October 2025

What is CVE-2025-33040?

A resource management vulnerability in Qsync Central allows remote attackers who gain user accounts to potentially exploit the system. By exploiting this flaw, attackers can monopolize resources, hindering access for legitimate applications and processes, which could lead to service disruptions. It's essential for users to update to Qsync Central version 5.0.0.1 or later to mitigate this risk. For more details, refer to the official security advisory.

Affected Version(s)

Qsync Central 4.x < 5.0.0.1 ( 2025/07/09 )

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

coral
.
CVE-2025-33040 : Resource Management Vulnerability in Qsync Central by QNAP