CVE-2025-33037: Qsync Central
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33037?
CVE-2025-33037 has a medium severity level due to its impact on the confidentiality of files and system data.
How do I fix CVE-2025-33037?
To fix CVE-2025-33037, upgrade Qsync Central to version 4.5.0.8 or later.
What is the impact of CVE-2025-33037?
The impact of CVE-2025-33037 allows attackers with user account access to read unexpected files or sensitive system data.
Who is affected by CVE-2025-33037?
CVE-2025-33037 affects users of Qsync Central prior to version 4.5.0.8.
Is there any workaround for CVE-2025-33037?
There are no known workarounds for CVE-2025-33037; the recommended action is to apply the software update.