Security ID : QSA-25-34
Multiple Vulnerabilities in Qsync Central
Release date : October 4, 2025
CVE identifier : CVE-2025-33034 | CVE-2025-33039 | CVE-2025-33040 | CVE-2025-44006 | CVE-2025-44007 | CVE-2025-44008 | CVE-2025-44009 | CVE-2025-44010 | CVE-2025-44011 | CVE-2025-44014
Affected products: Qsync Central 4.x
Severity
Moderate
Status
Resolved
Summary
Multiple vulnerabilities have been reported to affect Qsync Central:
- CVE-2025-33034: Path traversal vulnerability
If a remote attacker gains access to a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. - CVE-2025-33039, CVE-2025-33040, CVE-2025-44006, CVE-2025-44007: Allocation of resources without limits or throttling vulnerabilities
If a remote attacker gains access to a user account, they can then exploit the vulnerabilities to prevent other systems, applications, or processes from accessing the same type of resource. - CVE-2025-44008, CVE-2025-44009, CVE-2025-44010, CVE-2025-44011: NULL pointer dereference vulnerabilities
If a remote attacker gains access to a user account, they can then exploit the vulnerabilities to launch a denial-of-service (DoS) attack. - CVE-2025-44014: Out-of-bounds write vulnerability
If a remote attacker gains access to a user account, they can then exploit the vulnerability to modify or corrupt memory.
We have already fixed the vulnerabilities in the following version:
Affected Product | Fixed Version |
Qsync Central 4.x | Qsync Central 5.0.0.1 (2025/07/09) and later |
Recommendation
To fix the vulnerabilities, we recommend updating Qsync Central to the latest version.
Updating Qsync Central
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "Qsync Central" and then press ENTER.
Qsync Central appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your Qsync Central is already up to date. - Click OK.
The system updates the application.
Attachment
- CVE-2025-33034.json
- CVE-2025-33039.json
- CVE-2025-33040.json
- CVE-2025-44006.json
- CVE-2025-44007.json
- CVE-2025-44008.json
- CVE-2025-44009.json
- CVE-2025-44010.json
- CVE-2025-44011.json
- CVE-2025-44014.json
Acknowledgements: coral
Revision History:
V1.0 (October 4, 2025) - Published