Description
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.
Exploits (1)
References (5)
Core 5
Core References
Exploit x_refsource_misc
https://www.securify.nl/advisory/SFY20150810/synology_video_station_command_injection_and_multiple_sql_injection_vulnerabilities.html
Various Sources x_refsource_confirm
https://www.synology.com/en-global/releaseNote/VideoStation?model=DS715
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536427/100/0/threaded
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Sep/31
Scores
EPSS
0.2973
EPSS Percentile
96.7%
Details
CWE
CWE-77
Status
published
Products (1)
synology/video_station
< 1.5-0757
Published
Sep 11, 2015
Tracked Since
Feb 18, 2026