CVE-2025-54153: Qsync Central
Published Oct 3, 2025
·Updated
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.2 ( 2025/07/31 ) and later
Affected Software
2 affected components
Qsync Central<5.0.0.2
QNAP Qsync Central>=5.0.0.0<5.0.0.2
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 5.0.0.2 ( 2025/07/31 ) and later
Event History
Oct 3, 2025
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54153?
CVE-2025-54153 is ranked as a critical SQL injection vulnerability that can allow remote code execution.
2
How do I mitigate CVE-2025-54153?
To mitigate CVE-2025-54153, users should update to Qsync Central version 5.0.0.2 or later.
3
What software is impacted by CVE-2025-54153?
CVE-2025-54153 affects Qsync Central versions prior to 5.0.0.2.
4
Can CVE-2025-54153 be exploited without user credentials?
No, an attacker must first gain a valid user account to exploit CVE-2025-54153.
5
What are the potential consequences of CVE-2025-54153?
Exploitation of CVE-2025-54153 can lead to unauthorized code execution, compromising system integrity.