Subtitle File Information Disclosure in VideoPlayer2 by Synology
CVE-2025-29845
4.3MEDIUM
Key Information:
- Vendor
Synology
- Vendor
- CVE Published:
- 4 December 2025
What is CVE-2025-29845?
A security flaw in the VideoPlayer2 application enables remote authenticated users to read .srt subtitle files. This vulnerability could expose sensitive information contained within these files, leading to potential privacy and security concerns for users. As such, it is crucial for affected users to update their software promptly to mitigate any associated risks.
Affected Version(s)
Synology Router Manager (SRM) 1.3
Synology Router Manager (SRM) 1.3 < 1.3.1-9346-13
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Qian Chen (@cq674350529) from Codesafe Team of Legendsec at QI-ANXIN Group