CVE-2025-68406: Qsync Central
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68406?
CVE-2025-68406 is classified as a critical severity vulnerability due to its potential to allow remote attackers to read unexpected files.
How do I fix CVE-2025-68406?
To fix CVE-2025-68406, update Qsync Central to version 5.0.0.4 or later.
Who is affected by CVE-2025-68406?
CVE-2025-68406 affects users of Qsync Central versions prior to 5.0.0.4.
Can CVE-2025-68406 be exploited without login credentials?
No, CVE-2025-68406 requires a valid user account to exploit the path traversal vulnerability.
What type of attacks can CVE-2025-68406 facilitate?
CVE-2025-68406 can facilitate attacks that allow unauthorized reading of sensitive files and system data.