Seems like there is a more localized page available for your location.
Bee Series by Synology
Products A-Z

Synology-SA-25:08 BeeDrive for desktop

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Important
Status
Resolved

Abstract

Synology has released a security update for the BeeDrive desktop tool on Windows to address multiple vulnerabilities:
      • CVE-2025-54158 allows local users to execute arbitrary code.
      • CVE-2025-54159 allows remote attackers to delete arbitrary files.
      • CVE-2025-54160 allows local users to execute arbitrary code.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
BeeDrive for desktop Important Upgrade to 1.4.2-13960 or above.

Mitigation

None

Detail

Acknowledgement

  • CVE-2025-54158 : Zhao Runzi (赵润梓), 李建申(https://lsr00ter.github.io)

  • CVE-2025-54159, CVE-2025-54160 : Zhao Runzi (赵润梓)

Revision

Revision Date Description
1 2025-07-22 Initial public release.