CVE-2017-15893 is a directory traversal vulnerability affecting Synology File Station versions prior to 1.1.1-0099. This flaw allows remote authenticated users to write arbitrary files to the system by manipulating the dest_folder_path parameter during file extraction. With a CVSS score of 6.5 (Medium), it presents a moderate risk, as an attacker can achieve high integrity impact without requiring user interaction. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.1-0099CPE matchmatch criteria | cpe:2.3:a:synology:file_station:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.