An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
References
| Link | Resource |
|---|---|
| https://www.synology.com/en-global/security/advisory/Synology_SA_25_17 | Vendor Advisory |
Configurations
History
02 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. |
01 Jun 2026, 20:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.synology.com/en-global/security/advisory/Synology_SA_25_17 - Vendor Advisory | |
| First Time |
Synology
Synology assistant |
|
| CPE | cpe:2.3:a:synology:assistant:*:*:*:*:*:*:*:* |
27 May 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 09:16
Updated : 2026-06-02 16:09
NVD link : CVE-2025-66593
Mitre link : CVE-2025-66593
CVE.ORG link : CVE-2025-66593
JSON object : View
Products Affected
synology
- assistant
CWE
CWE-346
Origin Validation Error
