Synology-SA-25:05 Mail Server

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

Affected Products

Product Severity Fixed Release Availability
Synology Mail Server for DSM 7.2 Moderate Upgrade to 1.7.6-20676 or above.
Synology Mail Server for DSM 7.1 Moderate Upgrade to 1.7.6-10676 or above.

Mitigation

None

Detail

Acknowledgement

Chanin Kim of ENKI Whitehat

Reference

CVE-2025-2848

Revision

Revision Date Description
1 2025-03-27 Initial public release.
2 2025-12-04 Disclosed vulnerability details.