CVE-2025-58472: Qsync Central
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58472?
CVE-2025-58472 is classified as a high-severity vulnerability due to its potential for causing denial-of-service attacks.
How can I exploit CVE-2025-58472 if I gain an administrator account?
If you have an administrator account, you can exploit CVE-2025-58472 by triggering a NULL pointer dereference in Qsync Central.
What versions of Qsync Central are affected by CVE-2025-58472?
Qsync Central versions up to 5.0.0.4 are affected by CVE-2025-58472.
How do I fix CVE-2025-58472?
To fix CVE-2025-58472, you need to upgrade your Qsync Central software to a version that addresses this vulnerability.
Can CVE-2025-58472 lead to data loss?
While CVE-2025-58472 primarily causes denial-of-service, it could potentially lead to data loss if the service disruption affects ongoing operations.