Synology Diskstation Manager vulnerabilities
116 known vulnerabilities affecting synology/diskstation_manager.
Total CVEs
116
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
4
Severity breakdown
CRITICAL21HIGH51MEDIUM39LOW5
Vulnerabilities
Page 3 of 6
CVE-2022-27626P3HIGHCVSS 8.1fixed in 7.1.1-42962-2≥ unspecified, < 7.1.1-42962-22022-10-20
CVE-2022-27626 [HIGH] CWE-362 CVE-2022-27626: A vulnerability regarding concurrent execution using shared resource with improper synchronization (
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions
nvd
CVE-2022-27616P3HIGHCVSS 7.2≥ 6.2, < 6.2.4-25556-5≥ 7.0, < 7.0.1-42218-3+1 more2022-08-03
CVE-2022-27616 [HIGH] CWE-78 CVE-2022-27616: Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabi
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
nvd
CVE-2018-8916P3HIGHCVSS 8.8fixed in 6.2-23739≥ unspecified, < 6.2-237392018-06-08
CVE-2018-8916 [HIGH] CWE-620 CVE-2018-8916: Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) be
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification.
nvd
CVE-2021-26562P3HIGHCVSS 8.1fixed in 6.2.3-25426-32021-02-26
CVE-2021-26562 [HIGH] CWE-787 CVE-2021-26562: Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before
Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header.
nvd
CVE-2024-50629P3MEDIUMCVSS 5.3≥ 7.1, < 7.1.1-42962-7≥ 7.2, < 7.2-64570-4+3 more2025-03-19
CVE-2024-50629 [MEDIUM] CWE-116 CVE-2024-50629: Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation
Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.
nvd
CVE-2024-45538P3CRITICALCVSS 9.6≥ 7.2.1-69057, < 7.2.1-69057-2≥ 7.2.2-72803, < 7.2.2-72806+2 more2025-12-04
CVE-2024-45538 [CRITICAL] CWE-352 CVE-2024-45538: Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2021-26561P3HIGHCVSS 8.1fixed in 6.2.3-25426-32021-02-26
CVE-2021-26561 [HIGH] CWE-121 CVE-2021-26561: Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM
Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary code via syno_finder_site HTTP header.
nvd
CVE-2021-29083P3HIGHCVSS 7.2fixed in 6.2.3-25426-32021-04-01
CVE-2021-29083 [HIGH] CWE-78 CVE-2021-29083: Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Syno
Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter.
nvd
CVE-2025-1021P3HIGHCVSS 7.5≥ 7.1, < 7.1.1-42962-8≥ 7.2.1-69057, < 7.2.1-69057-7+2 more2025-04-23
CVE-2025-1021 [HIGH] CWE-862 CVE-2025-1021: Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-4
Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2022-27610P3HIGHCVSS 8.1≥ 6.2, < 6.2.3-25423≥ unspecified, < 6.2.3-254232022-07-27
CVE-2022-27610 [HIGH] CWE-22 CVE-2022-27610: Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in weba
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
nvd
CVE-2023-0142P3HIGHCVSS 8.1≥ 6.2, < 7.1-42661≥ 7.1, < 7.1-42661+2 more2023-06-13
CVE-2023-0142 [HIGH] CWE-427 CVE-2023-0142: Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskSt
Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with administrator privileges to read or write arbitrary files via unspecified vectors.
nvd
CVE-2026-40530P3HIGHCVSS 8.0≥ 7.3, < 7.3.2-86009-2≥ 7.2.2, < 7.2.2-72806-7+1 more2026-09-18
CVE-2026-40530 [HIGH] CWE-93 CVE-2026-40530: An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synolog
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.
nvd
CVE-2021-29084P3HIGHCVSS 7.5≥ 6.2, < 6.2.3-25426-3≥ unspecified, < 6.2.3-25426-32021-06-23
CVE-2021-29084 [HIGH] CWE-74 CVE-2021-29084: Improper neutralization of special elements in output used by a downstream component ('Injection') v
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2018-8919P3CRITICALCVSS 9.8fixed in 6.1.6-15266≥ unspecified, < 6.1.6-152662018-12-24
CVE-2018-8919 [CRITICAL] CWE-200 CVE-2018-8919: Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.
nvd
CVE-2017-9553P3HIGHCVSS 7.5≤ 6.1.1-15101-42017-07-24
CVE-2017-9553 [HIGH] CVE-2017-9553: A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.
nvd
CVE-2021-29087P3HIGHCVSS 7.5≥ 6.2, < 6.2.3-25426-3≥ unspecified, < 6.2.3-25426-32021-06-23
CVE-2021-29087 [HIGH] CWE-22 CVE-2021-29087: Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in weba
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files via unspecified vectors.
nvd
CVE-2017-12075P3HIGHCVSS 7.2fixed in 6.2-23739≥ unspecified, < 6.2-237392018-06-08
CVE-2017-12075 [HIGH] CWE-77 CVE-2017-12075: Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-2373
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.
nvd
CVE-2026-4036P3MEDIUMCVSS 6.5≥ 7.3, < 7.3.2-86009-2≥ 7.2.2, < 7.2.2-72806-7+1 more2026-09-18
CVE-2026-4036 [MEDIUM] CWE-89 CVE-2026-4036: An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerabilit
An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.
nvd
CVE-2021-29085P3HIGHCVSS 7.5≥ 6.2, < 6.2.3-25426-3≥ unspecified, < 6.2.3-25426-32021-06-23
CVE-2021-29085 [HIGH] CWE-74 CVE-2021-29085: Improper neutralization of special elements in output used by a downstream component ('Injection') v
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2012-1556P4MEDIUMCVSS 4.3PoCv3.2-19552014-09-12
CVE-2012-1556 [MEDIUM] CWE-79 CVE-2012-1556: Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.
nvd