{"id":"CVE-2025-30028","title":"A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.","summary":"A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-89"],"vendor":"synology","product":"active_backup_for_business","affected":["active_backup_for_business = 2.7.1-23234","active_backup_for_business = 2.7.1-13234","active_backup_for_business = 2.7.1-3234"],"published":"2026-05-27","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:10:00.190","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-30028","references":[{"url":"https://www.synology.com/en-global/security/advisory/Synology_SA_25_02","label":"security@synology.com"}],"tags":["nvd"],"epss":0.00368,"epssPercentile":0.28297,"ingestedAt":"2026-09-30T21:25:07.734Z","slug":"CVE-2025-30028","body":"## Overview\n\nA vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.\n\n## Affected\n\n- `active_backup_for_business = 2.7.1-23234`\n- `active_backup_for_business = 2.7.1-13234`\n- `active_backup_for_business = 2.7.1-3234`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}