216.73.216.197

CVE-2025-53594

· Published 02/01/2026 16:16 · Modified 02/01/2026 16:45

Labels: CVE-2025-53594 2026-01-02CVE-2025-53594CWE-22[email protected]

Essential information

Published
02/01/2026 16:16
Modified
02/01/2026 16:45
Author
Creator
CVSS
4.4 MEDIUM (v3) 4.4 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and later Qsync for Mac 5.1.5 and later QVPN Device Client for Mac 2.2.8 and later

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
qnap / qfinder pro mac cpe:2.3:a:qnap:qfinder_pro_mac:>=7.13.0:*:*:*:*:*:*:*
qnap / qsync for mac cpe:2.3:a:qnap:qsync_for_mac:>=5.1.5:*:*:*:*:*:*:*
qnap / qvpn device client for mac cpe:2.3:a:qnap:qvpn_device_client_for_mac:>=2.2.8:*:*:*:*:*:*:*

References