CVE-2025-54146: Qsync Central
Published Feb 11, 2026
·Updated
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
2 affected components
Qsync Central Qsync Central<5.0.0.4
QNAP Qsync Central>=5.0.0.0<5.0.0.4
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Event History
Feb 11, 2026
CVE Published
via MITRE·12:18 PM
Data Sourced
via MITRE·12:18 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54146?
CVE-2025-54146 has been categorized as a critical vulnerability due to its potential to enable a denial-of-service attack.
2
How do I fix CVE-2025-54146?
To fix CVE-2025-54146, upgrade Qsync Central to version 5.0.0.4 or later.
3
What type of attack can be executed using CVE-2025-54146?
CVE-2025-54146 can be exploited to launch a denial-of-service (DoS) attack.
4
Who is affected by CVE-2025-54146?
CVE-2025-54146 affects users of Qsync Central versions up to 5.0.0.4.
5
Can CVE-2025-54146 be exploited remotely?
Yes, CVE-2025-54146 can be exploited remotely if an attacker has a valid user account.