Synology

Security Scorecard

Score

100A

Total CVEs

10

Patch Rate

100%

10 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical1
High4
Medium5
Low0

Patch Status

Patched10 (100%)
Partial/Workaround0 (0%)
Unpatched0 (0%)

CVEs (10)

CVE IDTitleSeverityScoreDaysPatch
CVE-2024-5401-Medium4.3-Patched
CVE-2025-29845-Medium4.3-Patched
CVE-2024-45538Synology DiskStation Manager WebAPI Cross-Site Request Forgery (CSRF) VulnerabilityCritical9.6-Patched
CVE-2025-54158BeeDrive VulnerabilityHigh7.8-Patched
CVE-2024-45539Synology DiskStation Manager (DSM) CGI Component Denial-of-Service VulnerabilityHigh7.5-Patched
CVE-2025-54159BeeDrive Desktop VulnerabilityHigh7.5-Patched
CVE-2025-29846Synology Portenable CGI VulnerabilityHigh7.2-Patched
CVE-2025-2848Synology Mail Server Remote Authenticated Settings BypassMedium6.3-Patched
CVE-2025-8074BeeDrive Origin Validation Error VulnerabilityMedium5.6-Patched
CVE-2025-29843Synology FileStation Thumb CGI BypassMedium5.4-Patched