CVE-2025-1021: High severity synology photos diskstation manager vulnerability
Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1021?
CVE-2025-1021 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2025-1021?
To fix CVE-2025-1021, update your Synology DiskStation Manager to the latest versions: 7.1.1-42962-8, 7.2.1-69057-7, or 7.2.2-72806-3.
What types of attacks are possible with CVE-2025-1021?
CVE-2025-1021 allows remote attackers to read arbitrary files, potentially compromising sensitive data.
Which Synology DiskStation Manager versions are affected by CVE-2025-1021?
CVE-2025-1021 affects Synology DiskStation Manager versions before 7.1.1-42962-8, 7.2.1-69057-7, and 7.2.2-72806-3.
What is the potential impact of CVE-2025-1021 if exploited?
If exploited, CVE-2025-1021 can lead to unauthorized access to sensitive information stored on the affected Synology devices.