Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology router Manager
Synology safe Access |
|
| CPEs | cpe:2.3:a:synology:safe_access:*:*:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Synology router Manager
Synology safe Access |
Sat, 30 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology safeaccess |
|
| Vendors & Products |
Synology
Synology safeaccess |
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in Synology Safe Access Allows File Access and Limited Denial-of-Service |
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2026-05-27T13:44:57.358Z
Reserved: 2025-09-15T07:33:56.204Z
Link: CVE-2025-10466
Updated: 2026-05-27T13:44:51.076Z
Status : Analyzed
Published: 2026-05-27T09:16:26.230
Modified: 2026-06-17T08:28:22.833
Link: CVE-2025-10466
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:15:25Z