NULL Pointer Dereference in Qsync Central by QNAP
CVE-2025-54147
1.3LOW
What is CVE-2025-54147?
A NULL pointer dereference vulnerability has been identified in Qsync Central, affecting versions prior to 5.0.0.4. This flaw can be exploited by a remote attacker with valid user credentials, potentially leading to a denial-of-service (DoS) condition. By leveraging this vulnerability, an attacker could cause the application to crash, impacting service availability for legitimate users. Users are advised to update to version 5.0.0.4 or later to mitigate this risk.
Affected Version(s)
Qsync Central 5.0.x.x < 5.0.0.4 ( 2026/01/20 )