CVE-2025-54159
7.5Synology · BeeDrive for desktop
A missing authorization vulnerability in Synology BeeDrive for desktop allows remote, unauthenticated attackers to delete arbitrary files on the host system.
Executive summary
A critical missing authorization flaw in Synology BeeDrive for desktop enables unauthenticated remote attackers to delete arbitrary files, posing a severe risk to data integrity and system availability.
Vulnerability
The application fails to perform proper authorization checks, which allows an unauthenticated remote attacker to perform unauthorized file deletions. This flaw resides in the handling of requests within the desktop application.
Business impact
The ability for an unauthenticated remote attacker to delete arbitrary files carries a significant risk of data loss, potential system instability, and operational disruption. With a CVSS score of 7.5, this vulnerability is classified as High severity, reflecting the ease of exploitation (Network vector, Low complexity) and the significant impact on data integrity.
Remediation
Immediate Action: Update Synology BeeDrive for desktop to version 1.4.2-13960 or later immediately to resolve the missing authorization flaw.
Proactive Monitoring: Monitor system logs for unusual file deletion activity or unauthorized access attempts originating from external network sources.
Compensating Controls: Ensure that the host machine running BeeDrive is protected by a host-based firewall and that network access to the application is restricted to trusted segments to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the potential for unauthorized data destruction and the lack of required authentication for an attacker, this vulnerability represents a significant security risk. Organizations should prioritize updating all instances of Synology BeeDrive for desktop to the patched version 1.4.2-13960 as a matter of urgency to prevent potential exploitation.
More Synology CVEs
Sources
Originally found and disclosed by Zhao Runzi (赵润梓), per the CVE Program record.
- Synology-SA-25:08 BeeDrive for desktop Vendor advisory