CVE-2024-47265: Synology Active Backup For Business Agent

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.

Affected products

  • Synology Active Backup For Business Agent: before 2.7.1-13234 (fixed in 2.7.1-13234); before 2.7.1-3234 (fixed in 2.7.1-3234); before 2.7.1-23234 (fixed in 2.7.1-23234)

Published 2025-02-13. Last modified 2026-06-17.