CVE-2025-57710

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:43

Type Values Removed Values Added
Summary
  • (es) Se ha informado que una vulnerabilidad de asignación de recursos sin límites ni limitación afecta a Qsync Central. Si un atacante remoto obtiene una cuenta de administrador, puede entonces explotar la vulnerabilidad para evitar que otros sistemas, aplicaciones o procesos accedan al mismo tipo de recurso. Ya hemos corregido la vulnerabilidad en la siguiente versión: Qsync Central 5.0.0.4 ( 2026/01/20 ) y posteriores

12 Feb 2026, 14:41

Type Values Removed Values Added
CPE cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
References () https://www.qnap.com/en/security-advisory/qsa-26-02 - () https://www.qnap.com/en/security-advisory/qsa-26-02 - Vendor Advisory
First Time Qnap qsync Central
Qnap

11 Feb 2026, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 13:15

Updated : 2026-06-17 09:43


NVD link : CVE-2025-57710

Mitre link : CVE-2025-57710

CVE.ORG link : CVE-2025-57710


JSON object : View

Products Affected

qnap

  • qsync_central
CWE
CWE-770

Allocation of Resources Without Limits or Throttling