Path Traversal Flaw in Qsync Central by QNAP
CVE-2025-57712
4MEDIUM
What is CVE-2025-57712?
A path traversal vulnerability in Qsync Central allows authenticated remote attackers to read sensitive files or system data. If an attacker gains access to a user account, they can exploit this flaw to navigate unexpected directories and access unauthorized information. This issue has been addressed in version 5.0.0.3 and later.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Qsync Central 5.0.x.x < 5.0.0.3 ( 2025/08/28 )
References
CVSS V4
Score:
4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
coral