CVE-2025-52870

8.1

QNAP Systems Inc. · Qsync Central

A buffer overflow vulnerability in Qsync Central allows an authenticated remote attacker to crash processes or modify memory.

Executive summary

A buffer overflow vulnerability in QNAP Qsync Central versions prior to 5.0.0.4 poses a risk of service disruption or memory corruption for authenticated users.

Vulnerability

This vulnerability is a buffer overflow (CWE-120, CWE-122) that can be triggered by an authenticated remote attacker. The attacker must possess a valid user account to interact with the affected component and manipulate process memory.

Business impact

The exploitation of this flaw can lead to unauthorized modification of process memory or complete service failure, resulting in system instability and downtime. Given the CVSS score of 8.1, the vulnerability represents a significant risk to operational continuity for organizations relying on Qsync Central for data synchronization.

Remediation

Immediate Action: Update Qsync Central to version 5.0.0.4 or later as specified in the QNAP security advisory.

Proactive Monitoring: Review system and application access logs for unusual activity or frequent service crashes originating from authenticated user accounts.

Compensating Controls: Ensure that access to the Qsync Central interface is restricted to authorized personnel only, minimizing the attack surface available to potentially malicious actors.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this issue necessitates immediate attention from IT administrators. Organizations should prioritize updating the Qsync Central software to version 5.0.0.4 to eliminate the buffer overflow risk and prevent potential service disruption or unauthorized memory manipulation.

More QNAP Systems Inc. CVEs

Sources

Originally found and disclosed by Searat and izut, per the CVE Program record.