CVE-2025-29843: Path Traversal
Published Dec 4, 2025
·Updated
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
Affected Software
14 affected components
Synology Router Manager>=1.3<1.3.1-9346
Synology Router Manager=1.3.1-9346
Synology Router Manager=1.3.1-9346-update1
Synology Router Manager=1.3.1-9346-update10
Synology Router Manager=1.3.1-9346-update11
Synology Router Manager=1.3.1-9346-update12
Synology Router Manager=1.3.1-9346-update2
Synology Router Manager=1.3.1-9346-update3
Synology Router Manager=1.3.1-9346-update4
Synology Router Manager=1.3.1-9346-update5
Synology Router Manager=1.3.1-9346-update6
Synology Router Manager=1.3.1-9346-update7
Synology Router Manager=1.3.1-9346-update8
Synology Router Manager=1.3.1-9346-update9
Event History
Dec 4, 2025
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29843?
CVE-2025-29843 is classified as a high severity vulnerability due to its potential to allow unauthorized access to image files.
2
How do I fix CVE-2025-29843?
To resolve CVE-2025-29843, update your Synology Router Manager to the latest version as specified in the security advisory.
3
Who is affected by CVE-2025-29843?
CVE-2025-29843 affects remote authenticated users of specific versions of Synology Router Manager.
4
What type of attacks can be performed using CVE-2025-29843?
Exploiting CVE-2025-29843 allows attackers to read and write image files, potentially compromising sensitive data.
5
When was CVE-2025-29843 reported?
CVE-2025-29843 was reported as a vulnerability in Synology Router Manager affecting several specific versions.