We have already fixed the vulnerability in the following versions:
Qfinder Pro Mac 7.13.0 and later
Qsync for Mac 5.1.5 and later
QVPN Device Client for Mac 2.2.8 and later
Project Subscriptions
No advisories yet.
Solution
We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and later Qsync for Mac 5.1.5 and later QVPN Device Client for Mac 2.2.8 and later
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-55 |
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Qnap Qnap qfinder Pro Qnap qsync Qnap qvpn |
|
| Vendors & Products |
Apple
Apple macos Qnap Qnap qfinder Pro Qnap qsync Qnap qvpn |
Fri, 02 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and later Qsync for Mac 5.1.5 and later QVPN Device Client for Mac 2.2.8 and later | |
| Title | Qfinder Pro, Qsync, QVPN | |
| Weaknesses | CWE-22 CWE-367 CWE-59 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-01-02T19:12:02.094Z
Reserved: 2025-07-04T01:08:32.756Z
Link: CVE-2025-53594
Updated: 2026-01-02T19:11:57.428Z
Status : Awaiting Analysis
Published: 2026-01-02T16:16:59.567
Modified: 2026-01-02T16:45:26.640
Link: CVE-2025-53594
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:13:59Z