Skip to main content

CVE-2025-44006: CWE-770 in QNAP Systems Inc. Qsync Central

High
VulnerabilityCVE-2025-44006cvecve-2025-44006cwe-770
Published: Fri Oct 03 2025 (10/03/2025, 18:08:57 UTC)
Source: CVE Database V5
Vendor/Project: QNAP Systems Inc.
Product: Qsync Central

Description

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later

Technical Details

Data Version
5.1
Assigner Short Name
qnap
Date Reserved
2025-04-21T07:56:46.493Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68e065e211971642e8580b83

Added to database: 10/4/2025, 12:10:10 AM

Last updated: 10/4/2025, 12:10:10 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats