What are you looking for ?
facts 2025 and predictions 2026
RAIDON

Synology Security Advisories SA-25:14 and SA-25:13 on Resolved Vulnerabilities

Concerning DSM NAS OS and Synology Contacts package in DSM

Synology, Inc. had published 2 security advisories on resolved vulnerabilities.

Synology-SA-25:14 DSM (PWN2OWN 2025)

Publish Time: 2025-11-19 10:52:25 UTC+8
Last Updated:
2025-11-19 10:58:29 UTC+8
Severity:
Important
Status
: Resolved

Abstract
Synology has released a security update for the DSM to address ZDI-CAN-28409 :

      • CVE-2025-13392 allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).

Please refer to the ‘Affected Products’ table for the corresponding updates.

Affected Products:

Product

Severity

Fixed Release Availability

DSM 7.3

Important

Upgrade to 7.3.1-86003-1 or above.

DSM 7.2.2

Important

Upgrade to 7.2.2-72806-5 or above.

DSM 7.2.1

Not affected

N/A

Mitigation: None

Detail

Acknowledgement
Le Trong Phuc (chanze@VRC) and Cao Ngoc Quy (Chino Kafuu)

Revision

Revision

Date

Description

1

2025-11-19

Initial public release.

 

Synology-SA-25:13 Synology Contacts

Publish Time: 2025-11-14 16:59:36 UTC+8
Last Updated:
2025-11-14 17:00:42 UTC+8
Severity:
Moderate
Status
: Resolved

Abstract
Synology has released a security update for the Synology Contacts package in DSM to address a vulnerability:

      • CVE-2025-13167 allows remote authenticated users to read or write limited files.

Please refer to the ‘Affected Products’ table for the corresponding updates.

Affected Products:

Product

Severity

Fixed Release Availability

Synology Contacts for DSM 7.3

Moderate

Upgrade to 1.0.10-20659 or above.

Synology Contacts for DSM 7.2.2

Moderate

Upgrade to 1.0.10-20659 or above.

Synology Contacts for DSM 7.2.1

Moderate

Upgrade to 1.0.10-20659 or above.

Mitigation: None

Detail

Acknowledgement
Warisse Valentin (Aytio)

Revision

Revision

Date

Description

1

2025-11-14

Initial public release.

 

Articles_bottom
ExaGrid
AIC
ATTO
OPEN-E