CVE-2025-29846: Path Traversal
Published Dec 4, 2025
·Updated
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
Affected Software
14 affected components
Synology Router Manager>=1.3<1.3.1-9346
Synology Router Manager=1.3.1-9346
Synology Router Manager=1.3.1-9346-update1
Synology Router Manager=1.3.1-9346-update10
Synology Router Manager=1.3.1-9346-update11
Synology Router Manager=1.3.1-9346-update12
Synology Router Manager=1.3.1-9346-update2
Synology Router Manager=1.3.1-9346-update3
Synology Router Manager=1.3.1-9346-update4
Synology Router Manager=1.3.1-9346-update5
Synology Router Manager=1.3.1-9346-update6
Synology Router Manager=1.3.1-9346-update7
Synology Router Manager=1.3.1-9346-update8
Synology Router Manager=1.3.1-9346-update9
Event History
Dec 4, 2025
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29846?
The severity of CVE-2025-29846 is classified as medium, posing potential risk to authenticated users.
2
How do I fix CVE-2025-29846?
To fix CVE-2025-29846, you should update Synology Router Manager to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2025-29846?
CVE-2025-29846 affects users of Synology Router Manager versions 1.3.1-9346 and earlier.
4
What type of attack does CVE-2025-29846 enable?
CVE-2025-29846 enables remote authenticated users to obtain the status of installed packages, potentially exposing sensitive information.
5
When was CVE-2025-29846 discovered?
CVE-2025-29846 was discovered in 2025, following reports of unauthorized information access.