CVE-2025-48723
8.1QNAP · Qsync Central
A buffer overflow vulnerability in QNAP Qsync Central allows an authenticated attacker to modify memory or crash system processes.
Executive summary
QNAP Qsync Central is affected by a buffer overflow vulnerability that allows an authenticated attacker to compromise system stability through memory manipulation.
Vulnerability
The flaw is a buffer overflow (CWE-120, CWE-122) within Qsync Central. An attacker must possess a valid user account to trigger the vulnerability, which then allows for process crashing or memory modification.
Business impact
Successful exploitation of this vulnerability could lead to significant service disruption and potential system instability due to process crashes. While the CVSS score of 8.1 indicates a high severity, the requirement for an authenticated account limits the initial attack surface, though it remains a critical risk for internal environment integrity and uptime.
Remediation
Immediate Action: Update Qsync Central to version 5.0.0.4 or later immediately.
Proactive Monitoring: Monitor system logs for repeated process crashes or anomalous memory usage associated with the Qsync service.
Compensating Controls: Ensure strict access control policies are in place to prevent unauthorized users from obtaining valid credentials that could be used to trigger this vulnerability.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for process disruption and the availability of a vendor-supplied patch, administrators should prioritize updating Qsync Central to version 5.0.0.4. Organizations should verify that their user access management policies are robust to mitigate the risk posed by the required authentication step in the attack chain.
More QNAP CVEs
Sources
Originally found and disclosed by coral, per the CVE Program record.