CVE-2025-54148: Qsync Central
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54148?
CVE-2025-54148 is considered a high severity vulnerability, as it can lead to a denial-of-service (DoS) attack.
How do I fix CVE-2025-54148?
To fix CVE-2025-54148, you should upgrade to Qsync Central version 5.0.0.4 or later.
What kind of attack can be launched using CVE-2025-54148?
A remote attacker can exploit CVE-2025-54148 to launch a denial-of-service (DoS) attack.
Which versions of Qsync Central are affected by CVE-2025-54148?
CVE-2025-54148 affects Qsync Central versions from 5.0.0.0 up to but not including 5.0.0.4.
Can CVE-2025-54148 be exploited without a user account?
No, a remote attacker must gain a user account to exploit CVE-2025-54148.