CVE-2025-29843

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
synologyCNA
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
VendorProductVersion
synologyrouter_manager
1.3 ≤
𝑥
< 1.3.1-9346
synologyrouter_manager
1.3.1-9346
synologyrouter_manager
1.3.1-9346:update1
synologyrouter_manager
1.3.1-9346:update10
synologyrouter_manager
1.3.1-9346:update11
synologyrouter_manager
1.3.1-9346:update12
synologyrouter_manager
1.3.1-9346:update2
synologyrouter_manager
1.3.1-9346:update3
synologyrouter_manager
1.3.1-9346:update4
synologyrouter_manager
1.3.1-9346:update5
synologyrouter_manager
1.3.1-9346:update6
synologyrouter_manager
1.3.1-9346:update7
synologyrouter_manager
1.3.1-9346:update8
synologyrouter_manager
1.3.1-9346:update9
𝑥
= Vulnerable software versions