CVE-2025-58467: Qsync Central
A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58467?
CVE-2025-58467 is considered to be a critical vulnerability due to its potential to allow attackers to access sensitive files and system data.
How do I fix CVE-2025-58467?
To fix CVE-2025-58467, update Qsync Central to version 5.0.0.4 or later.
Who is affected by CVE-2025-58467?
CVE-2025-58467 affects users of Qsync Central versions up to 5.0.0.4.
What type of vulnerability is CVE-2025-58467?
CVE-2025-58467 is a relative path traversal vulnerability that can be exploited by remote attackers.
What should I do if I cannot update to fix CVE-2025-58467?
If you cannot update, immediate mitigation steps should include restricting access to Qsync Central and monitoring for any unauthorized activity.