CVE-2025-57710 PUBLISHED

Qsync Central

Assigner: qnap
Reserved: 18.08.2025 Published: 11.02.2026 Updated: 11.02.2026

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.

We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U
CVSS Score: 3.6

Product Status

Vendor QNAP Systems Inc.
Product Qsync Central
Versions Default: unaffected
  • affected from 5.0.x.x to 5.0.0.4 ( 2026/01/20 ) (excl.)

Solutions

We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later

Credits

  • coral finder

References

Problem Types

  • CWE-770 CWE

Impacts

  • CAPEC-131