« Volver al listado

Qnap

Qnap Qsync Central: vulnerabilidades y CVE

Qnap Qsync Central tiene 62 vulnerabilidades publicadas, 44 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE62
Últimos 12 meses44
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-68406Baja (1.3)0.57%—11 feb 2026
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-58472Baja (1.2)0.59%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS)…
CVE-2025-58471Baja (1.2)0.50%—11 feb 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-58470Baja (1.3)0.57%—11 feb 2026
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-58467Baja (1.3)0.44%—11 feb 2026
A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system…
CVE-2025-57711Baja (3.6)0.50%—11 feb 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-57710Baja (3.6)0.50%—11 feb 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent…
CVE-2025-57709Baja (1.3)0.58%—11 feb 2026
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2025-57708Baja (2.3)0.47%—11 feb 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other…
CVE-2025-54170Media (4.9)0.52%—11 feb 2026
An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the…
CVE-2025-54152Baja (1.3)0.40%—11 feb 2026
A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We…
CVE-2025-54151Media (4.9)0.26%—11 feb 2026
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.…
CVE-2025-54150Media (4.9)0.26%—11 feb 2026
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.…
CVE-2025-54149Media (4.9)0.26%—11 feb 2026
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.…
CVE-2025-54148Baja (1.3)0.50%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-54147Baja (1.3)0.42%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-54146Baja (1.3)0.50%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-53598Baja (0.6)0.50%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-52870Baja (0.6)0.40%—11 feb 2026
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2025-52869Baja (0.6)0.42%—11 feb 2026
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2025-52868Baja (0.6)0.32%—11 feb 2026
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2025-48724Baja (0.6)0.40%—11 feb 2026
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2025-48723Baja (0.6)0.40%—11 feb 2026
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed…
CVE-2025-48722Baja (1.3)0.42%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-47209Baja (1.3)0.42%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-30276Media (4.9)0.53%—11 feb 2026
An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the…
CVE-2025-30269Baja (0.6)0.30%—11 feb 2026
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify…
CVE-2025-30266Baja (0.6)0.42%—11 feb 2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have…
CVE-2025-57712Media (4)0.45%—7 nov 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
CVE-2025-54153Alta (8.6)0.42%—3 oct 2025
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services17
  2. T1059 Command and Scripting Interpreter5
  3. T1005 Data from Local System4
  4. T1499.004 Application or System Exploitation4
  5. T1499 Endpoint Denial of Service3
  6. T1203 Exploitation for Client Execution2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qnap