CVE-2025-33036: Qsync Central
Published Aug 29, 2025
·Updated
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Affected Software
2 affected components
Qsync Qsync Central<4.5.0.7
QNAP Qsync Central>=4.5.0.3<4.5.0.7
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Event History
Aug 29, 2025
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33036?
CVE-2025-33036 is classified as a medium severity path traversal vulnerability.
2
How do I fix CVE-2025-33036?
To fix CVE-2025-33036, upgrade Qsync Central to version 4.5.0.7 or later.
3
What type of vulnerability is CVE-2025-33036?
CVE-2025-33036 is a path traversal vulnerability that allows unauthorized access to files.
4
Who is affected by CVE-2025-33036?
Users of Qsync Central prior to version 4.5.0.7 are affected by CVE-2025-33036.
5
Can CVE-2025-33036 be exploited remotely?
Yes, CVE-2025-33036 can be exploited remotely if an attacker gains a user account.