Denial-of-Service Vulnerability in Qsync Central by QNAP
CVE-2025-52867

6MEDIUM

Key Information:

Vendor

QNAP

Vendor
CVE Published:
3 October 2025

What is CVE-2025-52867?

An uncontrolled resource consumption vulnerability exists in Qsync Central, allowing remote attackers with user accounts to exploit it and initiate denial-of-service (DoS) attacks, resulting in service disruptions. QNAP has addressed this issue in Qsync Central version 5.0.0.2 and later. It is crucial for users to update to the latest version to protect their systems from potential exploitation.

Affected Version(s)

Qsync Central 5.0.0 < 5.0.0.2 ( 2025/07/31 )

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Searat and izut
.
CVE-2025-52867 : Denial-of-Service Vulnerability in Qsync Central by QNAP