CVE-2025-33034: Qsync Central
Published Oct 3, 2025
·Updated
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
Affected Software
2 affected components
Qsync Qsync Central<5.0.0.1
QNAP Qsync Central>=4.2.0.0<5.0.0.1
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
Event History
Oct 3, 2025
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33034?
CVE-2025-33034 is categorized as a high severity path traversal vulnerability.
2
How do I fix CVE-2025-33034?
To fix CVE-2025-33034, upgrade Qsync Central to version 5.0.0.1 or later.
3
What type of vulnerability is CVE-2025-33034?
CVE-2025-33034 is a path traversal vulnerability that allows unauthorized file access.
4
Who is affected by CVE-2025-33034?
CVE-2025-33034 affects users of Qsync Central with vulnerable versions prior to 5.0.0.1.
5
What can an attacker do with CVE-2025-33034?
An attacker exploiting CVE-2025-33034 can read the contents of unexpected files or system data.