CVE-2024-53694: QNAP Systems Inc Qfinder Pro Mac
High severity, CVSS 8.6. EPSS: 0.1% chance of exploitation in the next 30 days.
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and later Qfinder Pro Mac 7.11.1 and later
Affected products
- QNAP Systems Inc Qfinder Pro Mac: from 7.11, before 7.11.1 (fixed in 7.11.1)
- QNAP Systems Inc Qsync For Mac: from 5.1, before 5.1.3 (fixed in 5.1.3)
- QNAP Systems Inc Qvpn Device Client For Mac: from 2.2, before 2.2.5 (fixed in 2.2.5)
Published 2025-03-07. Last modified 2026-06-17.