Qnap
Qnap Qsync Central: vulnerabilidades y CVE
Qnap Qsync Central tiene 62 vulnerabilidades publicadas, 44 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE62
Últimos 12 meses44
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-68406 | Baja (1.3) | 0.57% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-58472 | Baja (1.2) | 0.59% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS)… |
| CVE-2025-58471 | Baja (1.2) | 0.50% | — | 11 feb 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-58470 | Baja (1.3) | 0.57% | — | 11 feb 2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-58467 | Baja (1.3) | 0.44% | — | 11 feb 2026 | A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system… |
| CVE-2025-57711 | Baja (3.6) | 0.50% | — | 11 feb 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-57710 | Baja (3.6) | 0.50% | — | 11 feb 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent… |
| CVE-2025-57709 | Baja (1.3) | 0.58% | — | 11 feb 2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2025-57708 | Baja (2.3) | 0.47% | — | 11 feb 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other… |
| CVE-2025-54170 | Media (4.9) | 0.52% | — | 11 feb 2026 | An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the… |
| CVE-2025-54152 | Baja (1.3) | 0.40% | — | 11 feb 2026 | A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read sensitive portions of memory. We… |
| CVE-2025-54151 | Media (4.9) | 0.26% | — | 11 feb 2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.… |
| CVE-2025-54150 | Media (4.9) | 0.26% | — | 11 feb 2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.… |
| CVE-2025-54149 | Media (4.9) | 0.26% | — | 11 feb 2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.… |
| CVE-2025-54148 | Baja (1.3) | 0.50% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-54147 | Baja (1.3) | 0.42% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-54146 | Baja (1.3) | 0.50% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-53598 | Baja (0.6) | 0.50% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-52870 | Baja (0.6) | 0.40% | — | 11 feb 2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2025-52869 | Baja (0.6) | 0.42% | — | 11 feb 2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2025-52868 | Baja (0.6) | 0.32% | — | 11 feb 2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2025-48724 | Baja (0.6) | 0.40% | — | 11 feb 2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2025-48723 | Baja (0.6) | 0.40% | — | 11 feb 2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed… |
| CVE-2025-48722 | Baja (1.3) | 0.42% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-47209 | Baja (1.3) | 0.42% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-30276 | Media (4.9) | 0.53% | — | 11 feb 2026 | An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the… |
| CVE-2025-30269 | Baja (0.6) | 0.30% | — | 11 feb 2026 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify… |
| CVE-2025-30266 | Baja (0.6) | 0.42% | — | 11 feb 2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have… |
| CVE-2025-57712 | Media (4) | 0.45% | — | 7 nov 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We… |
| CVE-2025-54153 | Alta (8.6) | 0.42% | — | 3 oct 2025 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.