CVE-2025-30278: Qsync Central
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.
We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30278?
CVE-2025-30278 is considered a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-30278?
To fix CVE-2025-30278, upgrade Qsync Central to version 4.5.0.8 or later.
What does CVE-2025-30278 affect?
CVE-2025-30278 affects Qsync Central by allowing improper certificate validation.
Can CVE-2025-30278 be exploited by an unauthenticated user?
CVE-2025-30278 cannot be exploited by an unauthenticated user as it requires a user account to take advantage of the vulnerability.
What are the consequences of CVE-2025-30278?
The consequences of CVE-2025-30278 include potential loss of confidentiality and integrity of the system targeted by an attacker who exploits the vulnerability.