CVE-2025-29844 Details
Description
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
A vulnerability exists in the File Station component of Synology's SRM 1.3, allowing remote authenticated users to access file metadata and path information. This issue is categorized as a moderate severity path traversal vulnerability.
Users are advised to upgrade to Synology SRM version 1.3.1-9346-13 or above.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.synology.com/en-global/security/advisory/Synology_SA_25_04 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| synology router manager | >= 1.3, < 1.3.1-9346 1.3.1-9346 - 1.3.1-9346 update1 1.3.1-9346 update10 1.3.1-9346 update11 1.3.1-9346 update12 1.3.1-9346 update2 1.3.1-9346 update3 1.3.1-9346 update4 1.3.1-9346 update5 1.3.1-9346 update6 1.3.1-9346 update7 1.3.1-9346 update8 1.3.1-9346 update9 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | Initial Analysis | [email protected] |
| Dec 4, 2025 | New CVE Received | [email protected] |