CVE-2025-52868 is a high-severity buffer overflow vulnerability affecting QNAP Qsync Central. A remote attacker with a valid user account can exploit this flaw to modify memory or crash processes, leading to high integrity and availability impacts. The vulnerability has a CVSS score of 8.1 and is rated as high risk by FAUCET. While no public exploits or active exploitation have been observed, and community discussion is minimal, affected users should upgrade to Qsync Central 5.0.0.4 or later to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0.0, < 5.0.0.4CPE matchmatch criteria | cpe:2.3:a:qnap:qsync_central:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.