CVE-2025-33036 | QNAP Qsync Central 4.3.0.11/4.4.0.15/4.4.0.16_20240819/4.5.0.6 User Account path traversal (qsa-25-22)
A vulnerability identified as critical has been detected in QNAP Qsync Central 4.3.0.11/4.4.0.15/4.4.0.16_20240819/4.5.0.6. This affects an unknown function of the component User Account Handler. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2025-33036. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.