CVE-2025-54170: Qsync Central
Published Feb 11, 2026
·Updated
An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
2 affected components
Qsync Qsync Central<5.0.0.4
QNAP Qsync Central>=5.0.0.0<5.0.0.4
Remediation
Information
We have already fixed the vulnerability in the following version:
Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Event History
Feb 11, 2026
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54170?
CVE-2025-54170 is classified as a high-severity vulnerability due to the potential for remote exploitation by attackers.
2
How do I fix CVE-2025-54170?
To fix CVE-2025-54170, update Qsync Central to version 5.0.0.4 or later.
3
What type of vulnerability is CVE-2025-54170?
CVE-2025-54170 is an out-of-bounds read vulnerability.
4
Who is affected by CVE-2025-54170?
The vulnerability affects users of Qsync Central versions prior to 5.0.0.4.
5
What could happen if CVE-2025-54170 is exploited?
If exploited, CVE-2025-54170 could allow a remote attacker with user credentials to access confidential data.