Synology Diskstation Manager vulnerabilities
116 known vulnerabilities affecting synology/diskstation_manager.
Total CVEs
116
CISA KEV
1
actively exploited
Public exploits
11
Exploited in wild
4
Severity breakdown
CRITICAL21HIGH51MEDIUM39LOW5
Vulnerabilities
Page 5 of 6
CVE-2020-27653P3HIGHCVSS 8.3v6.2.3_254262020-10-29
CVE-2020-27653 [HIGH] CWE-327 CVE-2020-27653: Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
nvd
CVE-2020-27652P4HIGHCVSS 8.3≥ 6.2, < 6.2.3-25426-2≥ unspecified, < 6.2.3-25426-22020-10-29
CVE-2020-27652 [HIGH] CWE-327 CVE-2020-27652: Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
nvd
CVE-2026-40539P4HIGHCVSS 7.1≥ 7.3, < 7.3.2-86009-2≥ 7.2.2, < 7.2.2-72806-7+1 more2026-09-18
CVE-2026-40539 [HIGH] CWE-295 CVE-2026-40539: An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM)
An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.
nvd
CVE-2018-13286P4MEDIUMCVSS 6.5≥ 5.2, < 5.2-5967-8≥ 6.0, < 6.0.3-8754-8+3 more2019-04-01
CVE-2018-13286 [MEDIUM] CWE-276 CVE-2018-13286: Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) b
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
nvd
CVE-2026-13635P4MEDIUMCVSS 5.3≥ 7.4, < 7.4-90075≥ 7.3.2, < 7.3.2-86009-4+2 more2026-09-18
CVE-2026-13635 [MEDIUM] CWE-116 CVE-2026-13635: An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager
An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.
nvd
CVE-2022-22679P4MEDIUMCVSS 4.9≥ 6.2, < 6.2.4-25556-3≥ 7.0, < 7.0.1-42218-2+1 more2022-02-07
CVE-2022-22679 [MEDIUM] CWE-22 CVE-2022-22679: Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in supp
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to write arbitrary files via unspecified vectors.
nvd
CVE-2021-26563P4MEDIUMCVSS 6.7fixed in 6.2.4-25553≥ unspecified, < 6.2.4-255532021-02-26
CVE-2021-26563 [MEDIUM] CWE-863 CVE-2021-26563: Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) be
Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.
nvd
CVE-2018-7170P4MEDIUMCVSS 5.3≥ 5.2, < 6.1.6-152662018-03-06
CVE-2018-7170 [MEDIUM] CVE-2018-7170: ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the pr
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
nvd
CVE-2026-40533P4MEDIUMCVSS 5.3≥ 7.3, < 7.3.2-86009-2≥ 7.2.2, < 7.2.2-72806-7+1 more2026-09-18
CVE-2026-40533 [MEDIUM] CWE-202 CVE-2026-40533: An exposure of sensitive information through data queries vulnerability in Desktop API in Synology D
An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
nvd
CVE-2024-10445P4MEDIUMCVSS 5.3≥ 6.2, < 6.2.4-25556-8≥ 7.2, < 7.2-64570-4+4 more2025-03-19
CVE-2024-10445 [MEDIUM] CWE-295 CVE-2024-10445: Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS
Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.
nvd
CVE-2017-16766P4MEDIUMCVSS 6.5≥ 6.0.0, < 6.0.3-8754-6≥ 6.1.0, < 6.1.4-15217+2 more2017-12-22
CVE-2017-16766 [MEDIUM] CWE-284 CVE-2017-16766: An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) befo
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
nvd
CVE-2019-3870P4MEDIUMCVSS 6.1v5.2v6.1+1 more2019-04-09
CVE-2019-3870 [MEDIUM] CWE-276 CVE-2019-3870: A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2.
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permission
nvd
CVE-2015-2809P4MEDIUMCVSS 5.0≤ 3.02015-04-01
CVE-2015-2809 [MEDIUM] CWE-200 CVE-2015-2809: The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently re
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.
nvd
CVE-2021-26565P4MEDIUMCVSS 5.9fixed in 6.2.3-25426-32021-02-26
CVE-2021-26565 [MEDIUM] CWE-319 CVE-2021-26565: Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to obtain sensitive information via an HTTP session.
nvd
CVE-2018-13280P4MEDIUMCVSS 5.9fixed in 6.2-23739≥ unspecified, < 6.2-237392018-07-30
CVE-2018-13280 [MEDIUM] CWE-330 CVE-2018-13280: Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskSt
Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified vectors.
nvd
CVE-2026-40534P4MEDIUMCVSS 5.4≥ 7.3, < 7.3.2-86009-2≥ 7.2.2, < 7.2.2-72806-7+1 more2026-09-18
CVE-2026-40534 [MEDIUM] CWE-79 CVE-2026-40534: An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.
nvd
CVE-2021-43929P4MEDIUMCVSS 5.4≥ 6.2, < 6.2.4-25556-3≥ 7.0, < 7.0.1-42218-2+1 more2022-02-07
CVE-2021-43929 [MEDIUM] CWE-74 CVE-2021-43929: Improper neutralization of special elements in output used by a downstream component ('Injection') v
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2024-0854P4MEDIUMCVSS 5.4fixed in 7.2.1-69057-2≥ 7.2, < 7.2.1-69057-2+3 more2024-01-24
CVE-2024-0854 [MEDIUM] CWE-601 CVE-2024-0854: URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synolo
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified vectors.
nvd
CVE-2018-13281P4MEDIUMCVSS 4.3≥ 6.1, < 6.1.7-15284-2≥ 6.2, < 6.2-23739-2+3 more2018-10-31
CVE-2018-13281 [MEDIUM] CWE-200 CVE-2018-13281: Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.
nvd
CVE-2026-40536P4MEDIUMCVSS 4.3≥ 7.3, < 7.3.2-86009-2≥ 7.2.2, < 7.2.2-72806-7+1 more2026-09-18
CVE-2026-40536 [MEDIUM] CWE-22 CVE-2026-40536: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in A
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
nvd