CVE-2025-30275: Qsync Central
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30275?
CVE-2025-30275 is considered a medium severity vulnerability due to the potential of denial-of-service (DoS) attacks.
How do I fix CVE-2025-30275?
To fix CVE-2025-30275, upgrade to Qsync Central version 4.5.0.7 or later.
What is the nature of CVE-2025-30275?
CVE-2025-30275 is a NULL pointer dereference vulnerability that can be exploited by remote attackers with user accounts.
Who is affected by CVE-2025-30275?
Users of Qsync Central versions prior to 4.5.0.7 are affected by CVE-2025-30275.
Can CVE-2025-30275 lead to data loss?
While CVE-2025-30275 primarily allows for denial-of-service attacks, indirect data loss may occur depending on application handling during an attack.