Synology-SA-25:13 Synology Contacts

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

Synology has released a security update for the Synology Contacts package in DSM to address a vulnerability:
      • CVE-2025-13167 allows remote authenticated users to read or write limited files.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Synology Contacts for DSM 7.3 Moderate Upgrade to 1.0.10-20659 or above.
Synology Contacts for DSM 7.2.2 Moderate Upgrade to 1.0.10-20659 or above.
Synology Contacts for DSM 7.2.1 Moderate Upgrade to 1.0.10-20659 or above.

Mitigation

None

Detail

Acknowledgement

Warisse Valentin (Aytio)

Revision

Revision Date Description
1 2025-11-14 Initial public release.