CVE-2025-2848: Medium severity Synology Mail Server vulnerability
Published Dec 4, 2025
·Updated
A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.
Affected Software
4 affected components
All of the following
Synology Mail Server<1.7.6-10676
Synology Diskstation Manager=7.1
All of the following
Synology Mail Server<1.7.6-20676
Synology Diskstation Manager=7.2
Event History
Dec 4, 2025
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2848?
CVE-2025-2848 has a medium severity rating due to its ability to allow remote authenticated attackers to manipulate settings.
2
How do I fix CVE-2025-2848?
To fix CVE-2025-2848, update your Synology Mail Server to the latest version beyond 1.7.6-20676.
3
What specific settings can be affected by CVE-2025-2848?
CVE-2025-2848 allows attackers to read and write non-sensitive settings of the Synology Mail Server.
4
Is my Synology Diskstation Manager affected by CVE-2025-2848?
No, Synology Diskstation Manager versions 7.1 and 7.2 are not affected by CVE-2025-2848.
5
Who is at risk from CVE-2025-2848?
Remote authenticated users of Synology Mail Server versions older than 1.7.6-20676 are at risk from CVE-2025-2848.