Origin Validation Error in Synology Active Backup for Business Agent
CVE-2025-66592

6.1MEDIUM

What is CVE-2025-66592?

The Synology Active Backup for Business Agent is affected by an origin validation error, which allows local users to write arbitrary files during the installation process. This vulnerability can be leveraged to manipulate file contents and compromise system integrity, primarily affecting versions before 3.1.0-4967. Users are urged to update their software to mitigate potential risks.

Affected Version(s)

Synology Active Backup for Business Agent *

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sheikh Rishad (https://x.com/sheikhrishad0)
.