CVE-2025-29845Medium· 4.3▾ SunlitA vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
router_manager >= 1.3, < 1.3.1-9346router_manager = 1.3.1-9346Upgrade past the affected range:
router_manager 1.3.1-9346Connected by shared product, vendor, weakness, or advisory.
CVE-2025-29846High· 7.2A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
CVE-2025-29843Medium· 5.4A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
CVE-2025-29844Medium· 4.3A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
CVE-2025-54160High· 7.8Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
CVE-2026-40535Medium· 6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write …
CVE-2026-40536Medium· 4.3An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users t…