Path traversal in QNAP Systems, Inc. products - CVE-2025-53594
Published: January 5, 2026
Vulnerability identifier: #VU120950
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53594
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
QVPN Device Client for Mac
Qsync Client for Mac
Qfinder Pro for Mac
Qsync Client for Mac
Qfinder Pro for Mac
How to mitigate CVE-2025-53594
Install updates from vendor's website.
QVPN Device Client for Mac - update to 2.2.8
Qsync Client for Mac - update to 5.1.5
Qfinder Pro for Mac - update to 7.13.0
Qsync Client for Mac - update to 5.1.5
Qfinder Pro for Mac - update to 7.13.0