Synology: Two Security Advisories on Resolved Vulnerabilities
Concerning Synology Assistant and Active Backup for Business Agent
This is a Press Release edited by StorageNewsletter.com on December 16, 2025 at 2:00 pmSynology, Inc. had published 2 security advisory on resolved vulnerabilities.
Synology-SA-25:17 Synology Assistant
Publish Time: 2025-12-08 10:08:55 UTC+8
Last Updated: 2025-12-08 10:09:56 UTC+8
Severity: Moderate
Status: Resolved
Abstract
Synology has released a security update for the Assistant on Windows to address a vulnerability :
-
-
-
CVE-2025-66593 allows local users to write arbitrary files with restricted content.
-
-
Refer to the ‘Affected Products’ table for the corresponding updates.
Affected Products:
|
Product |
Severity |
Fixed Release Availability |
|---|---|---|
|
Synology Assistant |
Moderate |
Upgrade to 7.0.6-50085 or above. |
Mitigation: None
Detail
- CVE-2025-66593
- Severity: Moderate
- CVSS3 Base Score: 6.1
- CVSS3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
- CWE-346: Origin Validation Error
- ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Acknowledgement
Sheikh Rishad (https://x.com/sheikhrishad0)
Revision:
|
Revision |
Date |
Description |
|---|---|---|
|
1 |
2025-12-08 |
Initial public release. |
Synology-SA-25:16 Synology Active Backup for Business Agent
Publish Time: 2025-12-08 10:08:35 UTC+8
Last Updated: 2025-12-08 10:09:38 UTC+8
Severity: Moderate
Status: Resolved
Abstract
Synology has released a security update for the Active Backup for Business Agent on Windows to address a vulnerability :
-
-
-
CVE-2025-66592 allows local users to write arbitrary files with restricted content.
-
-
Refer to the ‘Affected Products’ table for the corresponding updates.
Affected Products
|
Product |
Severity |
Fixed Release Availability |
|---|---|---|
|
Synology Active Backup for Business Agent |
Moderate |
Upgrade to 3.1.0-4967 or above. |
Mitigation: None
Detail
- CVE-2025-66592
- Severity: Moderate
- CVSS3 Base Score: 6.1
- CVSS3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
- CWE-346: Origin Validation Error
- ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Acknowledgement
Sheikh Rishad (https://x.com/sheikhrishad0)
Revision:
|
Revision |
Date |
Description |
|---|---|---|
|
1 |
2025-12-08 |
Initial public release. |












