CNNVD-202512-511 Information

CNNVD ID

CNNVD-202512-511

CVE-2025-54158

  • CNNVD Published: 2025-12-04

Description (Chinese)

Synology BeeDrive是中国群晖(Synology)公司的一个备份与同步设备。 Synology BeeDrive 1.4.2-13960之前版本存在访问控制错误漏洞,该漏洞源于关键功能缺少身份验证,可能导致本地用户执行任意代码。

Description (English)

Synology BeeDrive is a backup and synchronized device for Synology. Prior to the version of Synology BeeDrive 1.4.2-1396, there was a bug in access control, which stemmed from the lack of authentication of key functions, which could lead local users to enforce arbitrary codes.

Hazard Level

Medium

Vulnerability Type

访问控制错误

Affected Vendor

群晖

Published

2025-12-04

Last Modified

2026-02-24

References

https://www.synology.com/en-global/security/advisory/Synology_SA_25_08

Patch

https://www.synology.com/en-global/security/advisory/Synology_SA_25_08

Share on: