CVE-2025-1021

Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

History

17 Nov 2025, 14:10

Type Values Removed Values Added
References () https://www.synology.com/en-global/security/advisory/Synology_SA_25_03 - () https://www.synology.com/en-global/security/advisory/Synology_SA_25_03 - Vendor Advisory
First Time Synology diskstation Manager
Synology
CPE cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

Information

Published : 2025-04-23 03:15

Updated : 2025-11-17 14:10


NVD link : CVE-2025-1021

Mitre link : CVE-2025-1021

CVE.ORG link : CVE-2025-1021


JSON object : View

Products Affected

synology

  • diskstation_manager
CWE
CWE-862

Missing Authorization