Synology-SA-25:11 Safe Access

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

Synology has released a security update for the Safe Access package in SRM to address a vulnerability:
      • CVE-2025-10466 allows remote authenticated users with administrator privileges to read or write limited files.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Safe Access for SRM 1.3 Moderate Upgrade to 1.3.1-0329 or above.

Mitigation

None

Detail

Acknowledgement

Only Hack in Cave (tr4ce(Jinho Ju), neko_hat(Dohwan Kim), tw0n3(Han Lee), Hc0wl(GangMin Kim)) (https://github.com/Team-OHiC)

Revision

Revision Date Description
1 2025-09-16 Initial public release.