CVE-2025-29877: File Station 5
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29877?
CVE-2025-29877 has been classified as a denial-of-service vulnerability that can potentially impact system availability.
How do I fix CVE-2025-29877?
To fix CVE-2025-29877, upgrade to Synology File Station version 5.5.6.4848 or later.
Who is affected by CVE-2025-29877?
CVE-2025-29877 affects users of Synology File Station versions up to 5.5.6.4847.
What kind of attacks can exploit CVE-2025-29877?
Exploitation of CVE-2025-29877 can lead to a remote denial-of-service attack against affected systems.
Is there a workaround for CVE-2025-29877?
There is no known workaround for CVE-2025-29877; users are advised to upgrade to the patched version.