Synology Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Synology products.
Products
- DiskStation Manager (DSM)53 vulnerabilities
- Synology Router Manager (SRM)43 vulnerabilities
- Surveillance Station25 vulnerabilities
- Synology Photo Station18 vulnerabilities
- Synology DiskStation Manager (DSM)13 vulnerabilities
- Photo Station12 vulnerabilities
- Camera Firmware9 vulnerabilities
- Drive7 vulnerabilities
- BeeDrive for desktop6 vulnerabilities
- Calendar6 vulnerabilities
- camera_firmware6 vulnerabilities
- router_manager6 vulnerabilities
- Synology Drive Client6 vulnerabilities
- Unified Controller (DSMUC)6 vulnerabilities
- Media Server5 vulnerabilities
- Synology Active Backup for Business Agent5 vulnerabilities
- Synology Calendar5 vulnerabilities
- Active Backup for Business4 vulnerabilities
- Note Station4 vulnerabilities
- active_backup_for_business_agent3 vulnerabilities
- Audio Station3 vulnerabilities
- BeeStation OS (BSM)3 vulnerabilities
- Download Station3 vulnerabilities
- Safe Access3 vulnerabilities
- Synology Download Station3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-4793HIGH | Generated title:Synology Assistant Incorrect Default Permissions Arbitrary File Read/Write and Denial-of-ServiceAn incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation. CWE-276Aug 3, 2026 | CVSS7.3v3.1 | EPSS0.134% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47263MEDIUM | Generated title:Synology Hyper Backup Path Traversal VulnerabilityAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors. CWE-22Jun 3, 2026 | CVSS4.1v3.1 | EPSS0.297% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47273MEDIUM | Generated title:Synology Hyper Backup Path Traversal VulnerabilityAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors. CWE-22Jun 3, 2026 | CVSS4.3v3.1 | EPSS0.277% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-49036HIGH | Generated title:Synology Active Backup for Business Recovery Media Creator OpenSSL Configuration Arbitrary Code ExecutionAn inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. CWE-829Jun 3, 2026 | CVSS7.8v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-49042HIGH | Generated title:Synology Hyper Backup Explorer MinGW DLL Inclusion of Functionality from Untrusted Control SphereAn inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors. CWE-829Jun 3, 2026 | CVSS7.8v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-52951MEDIUM | Generated title:Synology Note Station Client Cleartext Transmission of Sensitive InformationA cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential. CWE-319Jun 3, 2026 | CVSS5.9v3.1 | EPSS0.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2237MEDIUM | Generated title:Synology Storage Manager Information Disclosure via HTTP GET RequestA use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. CWE-598May 27, 2026 | CVSS6.2v3.1 | EPSS0.092% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66593MEDIUM | Generated title:Synology Assistant Origin Validation Error Arbitrary File Write and Denial of ServiceAn origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. CWE-346May 27, 2026 | CVSS6.1v3.1 | EPSS0.086% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66592MEDIUM | Generated title:Synology Active Backup for Business Agent Origin Validation Error Arbitrary File Write and Denial of ServiceAn origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. CWE-346May 27, 2026 | CVSS6.1v3.1 | EPSS0.086% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30028HIGH | Generated title:Synology Active Backup for Business Arbitrary File Read VulnerabilityA vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. CWE-89May 27, 2026 | CVSS8.6v3.1 | EPSS0.368% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-14713HIGH | Generated title:Synology C2 Identity Edge Server Exposed Dangerous Method or Function Credential DisclosureAn Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server. CWE-749May 27, 2026 | CVSS7.5v3.1 | EPSS0.475% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13593MEDIUM | Generated title:Synology ActiveProtect Agent Origin Validation Error Arbitrary File Write and Denial-of-ServiceOrigin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. CWE-346May 27, 2026 | CVSS6.1v3.1 | EPSS0.086% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-12686CRITICAL | Generated title:Synology BeeStation OS AdminCenter Classic Buffer Overflow Remote Code Execution VulnerabilityBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors. CWE-120May 27, 2026 | CVSS9.8v3.1 | EPSS2.76% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13392HIGH | Generated title:Synology DiskStation Manager SSO Improper Check for Unusual or Exceptional Conditions Authentication BypassImproper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN). CWE-754May 27, 2026 | CVSS8.1v3.1 | EPSS0.533% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13167MEDIUM | Generated title:Synology Contacts Cross-Site ScriptingImproper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors. CWE-79May 27, 2026 | CVSS5.4v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10466MEDIUM | Generated title:Synology Safe Access Cross-Site ScriptingImproper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information or conduct limited denial-of-service in SRM. CWE-79May 27, 2026 | CVSS5.9v3.1 | EPSS0.265% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Synology Surveillance Station IO Module Incorrect Authorization VulnerabilityIncorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. CWE-863May 27, 2026 | CVSS2.7v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-47271MEDIUM | Generated title:Synology Surveillance Station IPSpeaker Insufficiently Protected Credentials Information DisclosureInsufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. CWE-522May 27, 2026 | CVSS4.9v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Synology Surveillance Station Archiving Push Improper Permission Preservation Limited File WriteImproper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. CWE-281May 27, 2026 | CVSS2.7v3.1 | EPSS0.249% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-47269MEDIUM | Generated title:Synology Surveillance Station Cleartext Transmission of Sensitive Information in Export Key FunctionalityCleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. CWE-319May 27, 2026 | CVSS4.9v3.1 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47268MEDIUM | Generated title:Synology Surveillance Station AddOns Missing Authorization VulnerabilityMissing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors. CWE-862May 27, 2026 | CVSS4.9v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Synology Surveillance Station Archiving Pull Path TraversalImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors. CWE-22May 27, 2026 | CVSS2.7v3.1 | EPSS0.325% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-11399MEDIUM | Generated title:Synology BeeDrive for Desktop Files or Directories Accessible to External Parties Denial of Service VulnerabilityFiles or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks via unspecified vectors. CWE-552May 27, 2026 | CVSS6.8v3.1 | EPSS0.112% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-52945HIGH | Generated title:Synology BeeDrive for Desktop Uncontrolled Search Path VulnerabilityUncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors. CWE-427May 27, 2026 | CVSS7.8v3.1 | EPSS0.139% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-47961HIGH | Generated title:Synology SSL VPN Client Plaintext Storage of a PasswordA plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction. CWE-256Apr 10, 2026 | CVSS8.1v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |