CVE-2015-6912

Synology Video Station < 1.5-0757 - Command Injection

Title source: rule
STIX 2.1

Description

Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.

Exploits (1)

exploitdb WORKING POC
by Han Sahin · textwebappscgi
https://www.exploit-db.com/exploits/38128

Scores

EPSS 0.2973
EPSS Percentile 96.7%

Details

CWE
CWE-77
Status published
Products (1)
synology/video_station < 1.5-0757
Published Sep 11, 2015
Tracked Since Feb 18, 2026