Vulnerability Details CVE-2025-54160
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.3%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2025-54160
-
cpe:2.3:a:synology:beedrive:1.0.0-13176
-
cpe:2.3:a:synology:beedrive:1.1.0-13311
-
cpe:2.3:a:synology:beedrive:1.1.1-13312
-
cpe:2.3:a:synology:beedrive:1.2.0-13539
-
cpe:2.3:a:synology:beedrive:1.2.0-13547
-
cpe:2.3:a:synology:beedrive:1.2.1-13555
-
cpe:2.3:a:synology:beedrive:1.2.2-13557
-
cpe:2.3:a:synology:beedrive:1.3.0-13752
-
cpe:2.3:a:synology:beedrive:1.3.1-13808
-
cpe:2.3:a:synology:beedrive:1.3.2-13814
-
cpe:2.3:a:synology:beedrive:1.3.3-13815
-
cpe:2.3:a:synology:beedrive:1.4.0-13930
-
cpe:2.3:a:synology:beedrive:1.4.1-13931
-
cpe:2.3:a:synology:beedrive:1.4.1-13932