← Vulnerability feed

Vulnerability record · CVE-2025-29846 · published 4 December 2025

CVE-2025-29846: Synology router manager path traversal vulnerability

Synology · Router Manager

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

7.2 CVSS 3.1 High EPSS 0.64% · top 51.4% CWE-22 · Path traversal
7.2CVSS 3.1 base score
0.64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
25 Sep 2026Last modified by NVD

Description

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-29846 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-27655Synology router manager improper privilege management vulnerabilityImproper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via i…EPSS 1.8%9.8CVE-2023-32956Synology router manager vulnerabilityImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager …EPSS 1.5%9.8CVE-2023-0077Synology router manager vulnerabilityInteger overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote att…EPSS 0.95%9.8CVE-2020-27654Synology router manager improper privilege management vulnerabilityImproper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands…EPSS 4.7%9.8CVE-2018-1160Netatalk dsi_opensess.c out-of-bounds write allows remote code executionNetatalk before 3.1.12 fails to bounds-check attacker-controlled data in dsi_opensess.c, producing an out-of-bounds write. A remote unauthenticated a…EPSS 87%analysed9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed9.0CVE-2020-27649Synology router manager improper certificate validation vulnerabilityImproper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers…EPSS 0.72%8.8CVE-2023-41738Synology router manager vulnerabilityImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synolog…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2025-29846), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.