Synology
Synology Router Manager: vulnerabilidades y CVE
Synology Router Manager tiene 59 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE59
Últimos 12 meses4
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-29846 | Alta (7.2) | 0.64% | — | 4 dic 2025 | A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. |
| CVE-2025-29845 | Media (4.3) | 0.43% | — | 4 dic 2025 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. |
| CVE-2025-29844 | Media (4.3) | 0.43% | — | 4 dic 2025 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. |
| CVE-2025-29843 | Media (5.4) | 0.37% | — | 4 dic 2025 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. |
| CVE-2024-53288 | Media (5.9) | 0.21% | — | 23 jul 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with… |
| CVE-2024-53287 | Media (5.9) | 0.21% | — | 23 jul 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users… |
| CVE-2024-53286 | Alta (7.2) | 1.1% | — | 23 jul 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated… |
| CVE-2024-53285 | Media (5.9) | 0.27% | — | 9 dic 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users… |
| CVE-2024-53284 | Media (5.9) | 0.27% | — | 9 dic 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated… |
| CVE-2024-53283 | Media (5.9) | 0.27% | — | 9 dic 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated… |
| CVE-2024-53282 | Media (5.9) | 0.27% | — | 9 dic 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote… |
| CVE-2024-53281 | Media (5.9) | 0.27% | — | 9 dic 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to… |
| CVE-2024-53280 | Media (5.9) | 0.27% | — | 9 dic 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote… |
| CVE-2024-53279 | Media (5.9) | 0.27% | — | 9 dic 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users… |
| CVE-2024-11398 | Alta (8.1) | 0.65% | — | 4 dic 2024 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete… |
| CVE-2024-39348 | Alta (7.5) | 0.27% | — | 28 jun 2024 | Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary code via… |
| CVE-2024-39347 | Media (5.9) | 0.52% | — | 28 jun 2024 | Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet… |
| CVE-2023-41741 | Alta (7.5) | 0.72% | — | 31 ago 2023 | Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to obtain sensitive information via unspecified… |
| CVE-2023-41740 | Media (5.3) | 0.79% | — | 31 ago 2023 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to read specific files via… |
| CVE-2023-41739 | Media (6.5) | 0.78% | — | 31 ago 2023 | Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors. |
| CVE-2023-41738 | Alta (8.8) | 1.5% | — | 31 ago 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated… |
| CVE-2023-2729 | Alta (7.5) | 0.88% | — | 13 jun 2023 | Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors. |
| CVE-2023-0142 | Alta (8.1) | 0.97% | — | 13 jun 2023 | Uncontrolled search path element vulnerability in Backup Management functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7 and 7.1-42661 allows remote authenticated users with… |
| CVE-2023-32956 | Crítica (9.8) | 1.5% | — | 16 may 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to… |
| CVE-2023-32955 | Alta (8.1) | 1.2% | — | 16 may 2023 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client Functionality in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows… |
| CVE-2023-0077 | Crítica (9.8) | 0.95% | — | 5 ene 2023 | Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to overflow buffers via unspecified vectors. |
| CVE-2022-43932 | Alta (7.5) | 1.00% | — | 5 ene 2023 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote… |
| CVE-2020-27658 | Media (6.1) | 1.3% | — | 29 oct 2020 | Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information… |
| CVE-2020-27657 | Media (5.9) | 0.58% | — | 29 oct 2020 | Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via… |
| CVE-2020-27655 | Crítica (10) | 1.8% | — | 29 oct 2020 | Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic. |