Subtitle File Information Disclosure in VideoPlayer2 by Synology
CVE-2025-29845

4.3MEDIUM

Key Information:

Vendor

Synology

Vendor
CVE Published:
4 December 2025

What is CVE-2025-29845?

A security flaw in the VideoPlayer2 application enables remote authenticated users to read .srt subtitle files. This vulnerability could expose sensitive information contained within these files, leading to potential privacy and security concerns for users. As such, it is crucial for affected users to update their software promptly to mitigate any associated risks.

Affected Version(s)

Synology Router Manager (SRM) 1.3

Synology Router Manager (SRM) 1.3 < 1.3.1-9346-13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qian Chen (@cq674350529) from Codesafe Team of Legendsec at QI-ANXIN Group
.