CVE-2025-33038 | QNAP Qsync Central 4.3.0.11/4.4.0.15/4.4.0.16_20240819/4.5.0.6 User Account path traversal (qsa-25-22)
A vulnerability marked as critical has been reported in QNAP Qsync Central 4.3.0.11/4.4.0.15/4.4.0.16_20240819/4.5.0.6. Affected is an unknown function of the component User Account Handler. Performing manipulation results in path traversal.
This vulnerability is cataloged as CVE-2025-33038. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.