Synology Inc. operates a broadly deployed portfolio of network-attached storage, surveillance, and network management appliances that serve both consumer and enterprise environments, representing a large and widely embedded attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability. The exposure recurs across flagship products including DiskStation Manager, Surveillance Station, Photo Station, and Router Manager through a consistent set of web-application and system-command weakness classes: cross-site scripting, path traversal, SQL injection, OS command injection, and sensitive information exposure. These input-handling and access-control flaws reflect the web-facing management interfaces and integration points endemic to network appliances, and defenders should treat Synology appliance updates with high priority, particularly for internet-reachable instances. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Synology Inc. over time
Of all the CVEs published by Synology Inc. as a CNA, 100.0% affect products that Synology Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Synology Inc., 84.8% are self-published by Synology Inc. as a CNA.
Signals from CVEs in this vendor scope (355 CVEs).
355 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2020-1472CRITICAL An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc | Aug 17, 2020 | 10.0 | 99 | YES | YES |
CVE-2013-6955HIGH webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to | Jan 9, 2014 | 10.0 | 89 | NO | YES |
CVE-2017-14491CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | Oct 4, 2017 | 9.8 | 85 | NO | YES |
CVE-2018-1160CRITICAL Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attac | Dec 20, 2018 | 9.8 | 84 | NO | YES |
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2017-15889HIGH Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field. | Dec 4, 2017 | 8.8 | 83 | NO | YES |
CVE-2017-9554MEDIUM An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspeci | Jul 24, 2017 | 5.3 | 77 | NO | YES |
CVE-2021-44142HIGH The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileser | Feb 21, 2022 | 8.8 | 70 | NO | NO |
CVE-2019-9515HIGH Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF | Aug 13, 2019 | 7.5 | 66 | NO | NO |
Signals from CVEs in this vendor scope (355 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Synology Inc..
Media articles that mention a CVE ID that affects a product developed by Synology Inc. — matched by CVE ID, not by vendor name.