CVE-2025-54160

HIGH

Synology Beedrive < 1.4.2-13960 - Path Traversal

Title source: rule

Description

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 2.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-22
Status published

Affected Products (1)

synology/beedrive < 1.4.2-13960

Timeline

Published Dec 04, 2025
Tracked Since Feb 18, 2026