SQL Injection Vulnerability in Qsync Central by QNAP
CVE-2025-54153
8.6HIGH
What is CVE-2025-54153?
A SQL injection vulnerability has been discovered in Qsync Central, allowing remote attackers with user account access to execute unauthorized commands or code. This security flaw poses significant risks, necessitating immediate action to upgrade to version 5.0.0.2 or later, released on July 31, 2025, to mitigate potential exploitation.
Affected Version(s)
Qsync Central 5.0.0 < 5.0.0.2 ( 2025/07/31 )