CVE-2025-48722: Qsync Central
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48722?
CVE-2025-48722 has been classified as a medium severity vulnerability due to its potential for causing denial-of-service attacks.
How do I fix CVE-2025-48722?
To fix CVE-2025-48722, update Qsync Central to version 5.0.0.5 or later.
What is the impact of CVE-2025-48722 if exploited?
If exploited, CVE-2025-48722 allows an attacker with user access to perform a denial-of-service (DoS) attack.
Which versions of Qsync Central are affected by CVE-2025-48722?
CVE-2025-48722 affects Qsync Central versions up to 5.0.0.4.
Who is the vendor of the software affected by CVE-2025-48722?
The vendor of the affected software is QNAP, specifically for their Qsync Central product.