Skip to main content

Origin Validation Error

CVE-2025-13593

Severity Medium
Score 6.1/10

Summary

Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

  • LOW
  • LOCAL
  • LOW
  • UNCHANGED
  • REQUIRED
  • NONE
  • NONE
  • HIGH

CWE-346 - Origin Validation Error

The software does not properly verify that the source of data or communication is valid.

References

Advisory Timeline

  • Published