CVE-2025-54158

7.8

Synology · BeeDrive for desktop

A missing authentication vulnerability in Synology BeeDrive for desktop allows local users to execute arbitrary code via unspecified vectors.

Executive summary

A missing authentication flaw in Synology BeeDrive for desktop permits local users to achieve arbitrary code execution, posing a significant risk to system integrity.

Vulnerability

This vulnerability is classified as CWE-306, where a critical function fails to perform necessary authentication checks. An attacker with local access to the host machine can leverage this flaw to execute arbitrary code with the privileges of the affected application.

Business impact

The ability for a local user to execute arbitrary code represents a severe security risk, potentially leading to full system compromise, data theft, or the installation of malicious persistent software. With a CVSS score of 7.8, this vulnerability is classified as High severity. While the attack requires local access, the potential for total impact on confidentiality, integrity, and availability necessitates prompt remediation to prevent privilege escalation or lateral movement within the environment.

Remediation

Immediate Action: Update Synology BeeDrive for desktop to version 1.4.2-13960 or later immediately to resolve the authentication bypass.

Proactive Monitoring: Monitor local system logs for unusual process execution or attempts to interact with BeeDrive service components by unauthorized local users.

Compensating Controls: Implement strict access control policies on workstations to limit the number of local users, as the exploit vector requires local access to the system.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for arbitrary code execution, organizations should prioritize updating all instances of Synology BeeDrive for desktop. While the vulnerability requires local access, it remains a critical vector for privilege escalation and should be addressed by applying the vendor-provided update as soon as possible to minimize the attack surface.

More Synology CVEs

Sources

Originally found and disclosed by Zhao Runzi (赵润梓), 李建申(https://lsr00ter.github.io), per the CVE Program record.