CVE-2025-10466: XSS
Published May 27, 2026
·Updated
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM.
Affected Software
3 affected components
Synology Safe Access<1.3.1-0329
All of the following
Synology Safe Access<1.3.1-0329
Synology Router Manager=1.3
Event History
May 27, 2026
CVE Published
via MITRE·08:32 AM
Data Sourced
via MITRE·08:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-10466?
The severity of CVE-2025-10466 is rated as medium with a score of 5.9.
2
How do I fix CVE-2025-10466?
To fix CVE-2025-10466, update Synology Safe Access to version 1.3.1-0329 or later.
3
What type of vulnerability is CVE-2025-10466?
CVE-2025-10466 is a Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2025-10466?
Remote authenticated users with administrator privileges are affected by CVE-2025-10466.
5
What can an attacker do with CVE-2025-10466?
An attacker can read or write specific files containing non-sensitive information through CVE-2025-10466.