CVE-2025-29893: Qsync Central
Published Aug 29, 2025
·Updated
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Affected Software
2 affected components
Qsync Qsync Central<4.5.0.7
QNAP Qsync Central>=4.5.0.3<4.5.0.7
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Event History
Aug 29, 2025
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29893?
CVE-2025-29893 is considered a high-severity SQL injection vulnerability that can allow unauthorized code execution.
2
How do I fix CVE-2025-29893?
To fix CVE-2025-29893, upgrade to Qsync Central version 4.5.0.7 or later.
3
What systems are affected by CVE-2025-29893?
CVE-2025-29893 affects Qsync Central versions prior to 4.5.0.7.
4
Can remote attackers exploit CVE-2025-29893?
Yes, remote attackers with a user account can exploit CVE-2025-29893 to execute unauthorized commands.
5
What type of vulnerability is CVE-2025-29893?
CVE-2025-29893 is classified as an SQL injection vulnerability.