CVE-2025-54150

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:39

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de consumo de recursos no controlado ha sido reportada que afecta a Qsync Central. Si un atacante local obtiene una cuenta de usuario, puede entonces explotar la vulnerabilidad para lanzar un ataque de denegación de servicio (DoS). Ya hemos corregido la vulnerabilidad en la siguiente versión: Qsync Central 5.0.0.4 ( 2026/01/20 ) y posteriores

12 Feb 2026, 13:29

Type Values Removed Values Added
CPE cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:*
First Time Qnap qsync Central
Qnap
References () https://www.qnap.com/en/security-advisory/qsa-26-02 - () https://www.qnap.com/en/security-advisory/qsa-26-02 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

11 Feb 2026, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 13:15

Updated : 2026-06-17 09:39


NVD link : CVE-2025-54150

Mitre link : CVE-2025-54150

CVE.ORG link : CVE-2025-54150


JSON object : View

Products Affected

qnap

  • qsync_central
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-789

Memory Allocation with Excessive Size Value