CVE-2025-54160
7.8Synology · BeeDrive for desktop
A path traversal vulnerability in Synology BeeDrive for desktop allows local users to execute arbitrary code via unspecified vectors.
Executive summary
A path traversal vulnerability in Synology BeeDrive for desktop allows local attackers to achieve arbitrary code execution, posing a significant risk to system integrity.
Vulnerability
This is a path traversal vulnerability (CWE-22) that allows a local user with low privileges to manipulate file paths to execute arbitrary code on the host system.
Business impact
The ability for a local user to execute arbitrary code represents a total compromise of the affected host. Successful exploitation could lead to privilege escalation, unauthorized access to sensitive data stored on the machine, or the installation of persistent malicious software. Given the CVSS score of 7.8, this is a High severity issue that requires immediate attention to prevent local privilege escalation.
Remediation
Immediate Action: Update Synology BeeDrive for desktop to version 1.4.2-13960 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs for unauthorized file access attempts or the execution of unexpected processes originating from the BeeDrive application directory.
Compensating Controls: Ensure that appropriate host based access controls are enforced to limit user access to sensitive directories and restrict the execution of binaries by non-administrative users.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear risk of code execution for local users and should be addressed promptly. Organizations utilizing Synology BeeDrive for desktop should prioritize the deployment of the update to version 1.4.2-13960 to eliminate the underlying path traversal flaw and secure the host environment.
More Synology CVEs
Sources
Originally found and disclosed by Zhao Runzi (赵润梓), per the CVE Program record.
- Synology-SA-25:08 BeeDrive for desktop Vendor advisory