CVE-2025-29845: Path Traversal
Published Dec 4, 2025
·Updated
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
Affected Software
14 affected components
Synology Router Manager>=1.3<1.3.1-9346
Synology Router Manager=1.3.1-9346
Synology Router Manager=1.3.1-9346-update1
Synology Router Manager=1.3.1-9346-update10
Synology Router Manager=1.3.1-9346-update11
Synology Router Manager=1.3.1-9346-update12
Synology Router Manager=1.3.1-9346-update2
Synology Router Manager=1.3.1-9346-update3
Synology Router Manager=1.3.1-9346-update4
Synology Router Manager=1.3.1-9346-update5
Synology Router Manager=1.3.1-9346-update6
Synology Router Manager=1.3.1-9346-update7
Synology Router Manager=1.3.1-9346-update8
Synology Router Manager=1.3.1-9346-update9
Event History
Dec 4, 2025
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29845?
CVE-2025-29845 has been classified with a moderate severity rating due to the potential exposure of sensitive subtitle files.
2
How do I fix CVE-2025-29845?
To fix CVE-2025-29845, it is recommended to update the Synology Router Manager to the latest version that addresses this vulnerability.
3
Which versions are affected by CVE-2025-29845?
CVE-2025-29845 affects Synology Router Manager versions prior to 1.3.1-9346-update1.
4
Who can exploit CVE-2025-29845?
CVE-2025-29845 can be exploited by remote authenticated users to access .srt files.
5
What type of data is exposed by CVE-2025-29845?
CVE-2025-29845 allows unauthorized access to potentially sensitive subtitle files in .srt format.