CVE-2025-33038: Qsync Central
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33038?
CVE-2025-33038 has been classified as a high severity path traversal vulnerability.
How do I fix CVE-2025-33038?
To fix CVE-2025-33038, upgrade to version 4.5.0.7 or later of Qsync Central.
What can an attacker do with CVE-2025-33038?
An attacker who exploits CVE-2025-33038 can read unexpected files or system data if they gain a user account.
Which versions of Qsync Central are affected by CVE-2025-33038?
CVE-2025-33038 affects all versions of Qsync Central prior to 4.5.0.7.
Is there a workaround for CVE-2025-33038?
There are no known workarounds for CVE-2025-33038 other than upgrading to the fixed version.