Executive brief
Synology Active Backup for Business is a centralized backup solution for servers, virtual machines, and PCs. A security vulnerability allows an unauthorized person to remotely access and read files stored on the system without needing a password. This could lead to the theft of sensitive company data or backup archives, potentially compromising the entire organization's recovery strategy.
Technical details
A vulnerability classified as SQL Injection (CWE-89) exists in Synology Active Backup for Business. The flaw allows a remote, unauthenticated attacker to execute arbitrary SQL commands via the network. By exploiting this, an attacker can bypass authorization mechanisms to read arbitrary files from the underlying system. The vulnerability is addressed in versions 2.7.1-23234 (DSM 7.2), 2.7.1-13234 (DSM 7.1), and 2.7.1-3234 (DSM 6.2) or later.
Affected products
- Synology Active Backup for Business for DSM 7.2 before 2.7.1-23234
- Synology Active Backup for Business for DSM 7.1 before 2.7.1-13234
- Synology Active Backup for Business for DSM 6.2 before 2.7.1-3234
Timeline
- 2025-02-11: disclosed: Initial public release of advisory Synology-SA-25:02
- 2025-02-12: patched: Fixed versions released
- 2026-05-27: advisory: NVD publication and detailed disclosure