{"id":"CVE-2025-66592","title":"An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.","summary":"An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","cwe":["CWE-346"],"vendor":"synology","product":"active_backup_for_business_agent","affected":["active_backup_for_business_agent < 3.1.0-4967"],"patched":["active_backup_for_business_agent 3.1.0-4967"],"published":"2026-05-27","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:10:00.190","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66592","references":[{"url":"https://www.synology.com/en-global/security/advisory/Synology_SA_25_16","label":"security@synology.com"}],"tags":["nvd"],"epss":0.00086,"epssPercentile":0.003,"ingestedAt":"2026-09-30T21:25:07.735Z","slug":"CVE-2025-66592","body":"## Overview\n\nAn origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.\n\n## Affected\n\n- `active_backup_for_business_agent < 3.1.0-4967`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `active_backup_for_business_agent 3.1.0-4967`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}