CVE-2025-29892: Qsync Central
Published Jun 6, 2025
·Updated
An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later
Affected Software
2 affected components
QNAP Qsync Central<4.5.0.6
QNAP Qsync Central>=4.5.0.3<4.5.0.6
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 4.5.0.6 ( 2025/03/20 ) and later
Event History
Jun 6, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29892?
CVE-2025-29892 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2025-29892?
To fix CVE-2025-29892, update to Qsync Central version 4.5.0.6 or later.
3
What systems are affected by CVE-2025-29892?
CVE-2025-29892 affects QNAP Qsync Central versions prior to 4.5.0.6.
4
What could happen if CVE-2025-29892 is exploited?
If exploited, CVE-2025-29892 could allow remote attackers to execute unauthorized code or commands.
5
Is user access required to exploit CVE-2025-29892?
Yes, an attacker must have gained user access to exploit CVE-2025-29892.