QNAP Qsync Central Resource Exhaustion Vulnerability

Vulnerability

A vulnerability allowing resource exhaustion without limits or throttling has been identified in QNAP Qsync Central versions 4.x. This issue arises when a remote attacker with a user account exploits the vulnerability, causing a denial-of-service effect by preventing other systems, applications, or processes from accessing the same type of resource.

Impact

Exploitation of this vulnerability leads to resource exhaustion, causing a denial-of-service effect by blocking other systems, applications, or processes from accessing the same type of resource.

Remediation

Users are advised to update Qsync Central to version 5.0.0.1 or later. Instructions for updating Qsync Central are available on the QNAP website.

Added: Oct 3, 2025, 6:19 PM
Updated: Oct 3, 2025, 6:19 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.