PT-2025-49038 · Synology · Synology Beedrive

Zhao Runzi

·

Published

2025-12-04

·

Updated

2026-02-04

·

CVE-2025-54159

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Synology BeeDrive for desktop versions prior to 1.4.2-13960
Description A missing authorization flaw exists in BeeDrive. This allows remote attackers to delete arbitrary files through unspecified means.
Recommendations Update Synology BeeDrive for desktop to version 1.4.2-13960 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-54159

Affected Products

Synology Beedrive