Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-29892


An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later


Published

2025-06-06T16:15:25.783

Last Modified

2025-09-20T03:34:14.103

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap qsync_central < 4.5.0.6 Yes

References