CVE-2025-48724: Qsync Central
Published Feb 11, 2026
·Updated
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
2 affected components
Qsync Qsync Central<5.0.0.4
QNAP Qsync Central>=5.0.0.0<5.0.0.4
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Event History
Feb 11, 2026
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48724?
CVE-2025-48724 has a high severity rating due to its potential for exploitation by remote attackers.
2
How do I fix CVE-2025-48724?
To fix CVE-2025-48724, upgrade to Qsync Central version 5.0.0.4 or later.
3
What can an attacker do if they exploit CVE-2025-48724?
If exploited, an attacker can modify memory or crash processes on the affected system.
4
Is Qsync Central version 5.0.0.4 vulnerable to CVE-2025-48724?
No, Qsync Central version 5.0.0.4 or later is not vulnerable to CVE-2025-48724.
5
What should I do if I can't upgrade to the fixed version for CVE-2025-48724?
If you cannot upgrade, consider implementing network controls to mitigate potential exploit attempts.