Junglewise Threat Intelligence

CVE-2025-10466: Synology Safe Access cross-site scripting in SRM

CVE-2025-10466 · Severity: medium · CVSS 5.9 · Published 2026-05-27

Vendors: Synology.

Executive brief

Synology Safe Access, a security and parental control package for Synology routers, contains a vulnerability that could allow an administrator to perform unauthorized actions. By exploiting this flaw, a remote user with administrative privileges could read or write certain non-sensitive files or cause a limited service disruption. This could lead to minor data manipulation or temporary unavailability of the router's management features.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Synology Safe Access before version 1.3.1-0329 due to improper neutralization of input during web page generation. The vulnerability (CWE-79) requires the attacker to have remote authenticated access with administrator privileges and involves user interaction (UI:R). Successful exploitation allows an attacker to read or write specific files containing non-sensitive information or conduct a limited denial-of-service (DoS) within the Synology Router Manager (SRM) environment. The issue is resolved in Safe Access version 1.3.1-0329.

Affected products

  • Synology Safe Access for SRM 1.3 before 1.3.1-0329

Timeline

  • 2025-09-16: advisory: Initial public release of the advisory.
  • 2026-05-27: disclosed: Vulnerability details disclosed and CVE published.

References