CVE-2025-54152: Qsync Central
A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54152?
CVE-2025-54152 is considered a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-54152?
To fix CVE-2025-54152, update Qsync Central to version 5.0.0.4 or later.
Which versions of Qsync Central are affected by CVE-2025-54152?
CVE-2025-54152 affects Qsync Central versions prior to 5.0.0.4.
Can CVE-2025-54152 be exploited without user credentials?
No, CVE-2025-54152 requires a remote attacker to have a valid user account to exploit the vulnerability.
What type of data can be accessed if CVE-2025-54152 is exploited?
If exploited, CVE-2025-54152 may allow attackers to read sensitive portions of the system's memory.