CVE-2025-54159: High severity Synology BeeDrive vulnerability
Published Dec 4, 2025
·Updated
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.
Affected Software
2 affected components
Synology BeeDrive<1.4.2-13960
Synology BeeDrive<1.4.2-13960
Event History
Dec 4, 2025
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54159?
CVE-2025-54159 has been classified as a critical severity vulnerability due to the potential for remote file deletion.
2
How do I fix CVE-2025-54159?
To fix CVE-2025-54159, update Synology BeeDrive to version 1.4.2-13960 or later.
3
What is CVE-2025-54159?
CVE-2025-54159 is a missing authorization vulnerability in Synology BeeDrive that allows remote attackers to delete arbitrary files.
4
Who is affected by CVE-2025-54159?
Users of Synology BeeDrive for desktop prior to version 1.4.2-13960 are affected by CVE-2025-54159.
5
What can attackers do with CVE-2025-54159?
Attackers can exploit CVE-2025-54159 to remotely delete arbitrary files on affected systems.