CVE-2025-66593: Medium severity Synology Synology Assistant vulnerability
Published May 27, 2026
·Updated
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Affected Software
2 affected components
Synology Synology Assistant<7.0.6-50085
Synology Assistant<7.0.6-50085
Event History
May 27, 2026
CVE Published
via MITRE·08:43 AM
Data Sourced
via MITRE·08:43 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66593?
The severity of CVE-2025-66593 is medium, with a score of 6.1.
2
How do I fix CVE-2025-66593?
To fix CVE-2025-66593, update Synology Assistant to version 7.0.6-50085 or later.
3
What systems are affected by CVE-2025-66593?
CVE-2025-66593 affects local users of Synology Assistant prior to version 7.0.6-50085.
4
What type of vulnerability is CVE-2025-66593?
CVE-2025-66593 is an origin validation error vulnerability.
5
What are the potential consequences of CVE-2025-66593?
CVE-2025-66593 allows local users to write arbitrary files with restricted content during installation, which may lead to unauthorized access or system compromise.