PT-2025-13167 · Synology · Synology Mail Server

Chanin Kim

·

Published

2025-03-27

·

Updated

2025-12-04

·

CVE-2025-2848

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Synology Mail Server versions prior to DSM 7.2/7.1
Description A vulnerability in Synology Mail Server allows authenticated users to tamper with system configurations, risking mail stability. The issue can be exploited by remote attackers, potentially compromising system configurations and service stability.
Recommendations Upgrade to secure systems running DSM 7.2/7.1 to resolve the issue. As a temporary workaround, consider restricting access to configuration settings until a patch is available.

Fix

Missing Authentication

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-10542
CVE-2025-2848

Affected Products

Synology Mail Server