Resource Throttling DoS in Qsync Central <5.2.0.1 via Admin Access
CVE-2025-58471 Published on February 11, 2026
Qsync Central
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource.
We have already fixed the vulnerability in the following version:
Qsync Central 5.2.0.1 ( 2025/12/21 ) and later
Weakness Type
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Products Associated with CVE-2025-58471
Want to know whenever a new CVE is published for QNAP Qsync Central? stack.watch will email you.
Affected Versions
QNAP Systems Inc. Qsync Central:- Version 5.2.x.x and below 5.2.0.1 ( 2025/12/21 ) is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.