CVE-2025-53595: Qsync Central
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53595?
CVE-2025-53595 has been classified as a critical SQL injection vulnerability that could allow unauthorized code execution.
How do I fix CVE-2025-53595?
To fix CVE-2025-53595, upgrade to Qsync Central version 5.0.0.2 or later.
What are the risks associated with CVE-2025-53595?
If exploited, CVE-2025-53595 can allow an attacker to execute arbitrary commands using a compromised user account.
Who is affected by CVE-2025-53595?
CVE-2025-53595 affects users of Qsync Central prior to version 5.0.0.2.
Can CVE-2025-53595 be exploited remotely?
Yes, CVE-2025-53595 can be exploited remotely by an attacker with a user account.