NULL Pointer Dereference Vulnerability in Qsync Central by QNAP
CVE-2025-54148
1.3LOW
What is CVE-2025-54148?
A NULL pointer dereference vulnerability has been identified in Qsync Central that can be exploited by an authenticated remote attacker. This flaw can lead to a denial-of-service (DoS) condition, affecting the availability of the service. Users should upgrade to Qsync Central version 5.0.0.4 or later to mitigate this risk. For more information, refer to the official QNAP security advisory.
Affected Version(s)
Qsync Central 5.0.x.x < 5.0.0.4 ( 2026/01/20 )