Synology VideoPlayer2 Subtitle CGI Path Traversal Vulnerability Allowing Unauthorized File Access

Vulnerability

A path traversal vulnerability has been identified in the VideoPlayer2 subtitle CGI component of Synology routers running SRM 1.3. This vulnerability allows remote authenticated users to read .srt subtitle files, potentially leading to unauthorized access to sensitive information. The issue arises from improper validation of file paths, enabling users to manipulate file requests and access restricted files.

Impact

Exploitation of this vulnerability could result in unauthorized access to .srt files, which may contain sensitive information.

Remediation

Users are advised to upgrade to Synology SRM version 1.3.1-9346-13 or above.

Added: Dec 4, 2025, 3:26 PM
Updated: Dec 4, 2025, 6:20 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
4.9
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.