NULL Pointer Dereference Vulnerability in Qsync Central by QNAP
CVE-2025-48722
1.3LOW
What is CVE-2025-48722?
A vulnerability has been identified in Qsync Central by QNAP, where a NULL pointer dereference can be exploited by remote attackers to launch denial-of-service (DoS) attacks. This happens if an attacker gains access to a valid user account, subsequently leading to service interruptions. Users are advised to update to version 5.0.0.4 or later to mitigate this risk and ensure the continued security of their systems.
Affected Version(s)
Qsync Central 5.0.x.x < 5.0.0.4 ( 2026/01/20 )