A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.CreditsQian Chen (@cq674350529) from Codesafe Team of Legendsec at QI-ANXIN GroupReferenceshttps://www.synology.com/en-global/security/advisory/Synology_SA_25_04