CVE-2025-58470: Qsync Central
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58470?
CVE-2025-58470 is considered a high severity vulnerability due to its potential for remote exploitation and unauthorized file access.
How do I fix CVE-2025-58470?
To fix CVE-2025-58470, update Qsync Central to version 5.0.0.4 or later.
Who is affected by CVE-2025-58470?
CVE-2025-58470 affects users of Qsync Central software versions prior to 5.0.0.4.
What can an attacker do by exploiting CVE-2025-58470?
An attacker who exploits CVE-2025-58470 can read the contents of unexpected files or system data from Qsync Central.
Is there a workaround for CVE-2025-58470 until a fix is applied?
Currently, there are no known workarounds for CVE-2025-58470, so updating the software is the recommended action.