CVE-2025-29844: Path Traversal
Published Dec 4, 2025
·Updated
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
Affected Software
14 affected components
Synology Router Manager>=1.3<1.3.1-9346
Synology Router Manager=1.3.1-9346
Synology Router Manager=1.3.1-9346-update1
Synology Router Manager=1.3.1-9346-update10
Synology Router Manager=1.3.1-9346-update11
Synology Router Manager=1.3.1-9346-update12
Synology Router Manager=1.3.1-9346-update2
Synology Router Manager=1.3.1-9346-update3
Synology Router Manager=1.3.1-9346-update4
Synology Router Manager=1.3.1-9346-update5
Synology Router Manager=1.3.1-9346-update6
Synology Router Manager=1.3.1-9346-update7
Synology Router Manager=1.3.1-9346-update8
Synology Router Manager=1.3.1-9346-update9
Event History
Dec 4, 2025
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29844?
CVE-2025-29844 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2025-29844?
To fix CVE-2025-29844, update your Synology Router Manager to the latest version available.
3
Who is affected by CVE-2025-29844?
CVE-2025-29844 affects users of Synology Router Manager versions 1.3.1-9346 and earlier.
4
What type of attack does CVE-2025-29844 facilitate?
CVE-2025-29844 permits remote authenticated users to access file metadata and path information.
5
Is CVE-2025-29844 easy to exploit?
CVE-2025-29844 may be exploited easily if an attacker has authenticated access to the vulnerable system.