CVE-2025-54160

7.8

Synology · BeeDrive for desktop

A path traversal vulnerability in Synology BeeDrive for desktop allows local users to execute arbitrary code via unspecified vectors.

Executive summary

A path traversal vulnerability in Synology BeeDrive for desktop allows local attackers to achieve arbitrary code execution, posing a significant risk to system integrity.

Vulnerability

This is a path traversal vulnerability (CWE-22) that allows a local user with low privileges to manipulate file paths to execute arbitrary code on the host system.

Business impact

The ability for a local user to execute arbitrary code represents a total compromise of the affected host. Successful exploitation could lead to privilege escalation, unauthorized access to sensitive data stored on the machine, or the installation of persistent malicious software. Given the CVSS score of 7.8, this is a High severity issue that requires immediate attention to prevent local privilege escalation.

Remediation

Immediate Action: Update Synology BeeDrive for desktop to version 1.4.2-13960 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs for unauthorized file access attempts or the execution of unexpected processes originating from the BeeDrive application directory.

Compensating Controls: Ensure that appropriate host based access controls are enforced to limit user access to sensitive directories and restrict the execution of binaries by non-administrative users.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a clear risk of code execution for local users and should be addressed promptly. Organizations utilizing Synology BeeDrive for desktop should prioritize the deployment of the update to version 1.4.2-13960 to eliminate the underlying path traversal flaw and secure the host environment.

More Synology CVEs

Sources

Originally found and disclosed by Zhao Runzi (赵润梓), per the CVE Program record.