CVE-2025-1021
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 23, 2025
CWE ID 862
Summary
CVE-2025-1021 is a missing authorization vulnerability affecting Synology DiskStation Manager (DSM) versions before 7.1.1-42962-8, 7.2.1-69057-7, and 7.2.2-72806-3. This issue enables remote attackers to gain unauthorized access to read arbitrary files using unspecified vectors, posing a significant risk to data confidentiality. The vulnerability underscores the importance of maintaining up-to-date software to protect against potential cyber attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.