CVE-2025-54152

A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:39

Type Values Removed Values Added
Summary
  • (es) Se ha informado que una vulnerabilidad de uso de desplazamiento de puntero fuera de rango afecta a Qsync Central. Si un atacante remoto obtiene una cuenta de usuario, puede entonces explotar la vulnerabilidad para leer porciones sensibles de la memoria. Ya hemos corregido la vulnerabilidad en la siguiente versión: Qsync Central 5.0.0.4 ( 2026/01/20 ) y posteriores

12 Feb 2026, 13:28

Type Values Removed Values Added
CPE cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://www.qnap.com/en/security-advisory/qsa-26-02 - () https://www.qnap.com/en/security-advisory/qsa-26-02 - Vendor Advisory
First Time Qnap qsync Central
Qnap

11 Feb 2026, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 13:15

Updated : 2026-06-17 09:39


NVD link : CVE-2025-54152

Mitre link : CVE-2025-54152

CVE.ORG link : CVE-2025-54152


JSON object : View

Products Affected

qnap

  • qsync_central
CWE
CWE-823

Use of Out-of-range Pointer Offset