Diskstation Manager Unified Controller

Vendor:

First CVE: Jan 26, 2021 · Active for 5 years

21
Total CVEs
More Total CVEs than 94% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
4.8%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Diskstation Manager Unified Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2021
5 years ago
Most Recent CVE
Dec 4, 2025
234 days ago

CVE Severity & Scoring

Diskstation Manager Unified Controller21 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local3 (14.3%)
Network18 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (71.4%)
High6 (28.6%)
Unknown0 (0.0%)
User Interaction
None20 (95.2%)
Unknown0 (0.0%)
Required1 (4.8%)
Privileges Required
Low4 (19.0%)
High1 (4.8%)
None16 (76.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) b
Mar 19, 202510.033NONO
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMU
Dec 4, 20259.631NONO
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allo
Mar 25, 20229.831NONO
Use after free vulnerability in file transfer protocol component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via un
Jun 23, 20219.828NONO
Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-7280
Dec 4, 20258.827NONO
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execu
Feb 26, 20219.027NONO
Cleartext transmission of sensitive information vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to spoof s
Feb 26, 20218.727NONO
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-
Dec 4, 20257.526NONO
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user cre
Jun 13, 20237.525NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
1 CVE
4.8% of CVEs· 97th percentile
Metasploit
1 CVE
4.8% of CVEs· 96th percentile
Nuclei
1 CVE
4.8% of CVEs· 97th percentile
ExploitDB
1 CVE
4.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Diskstation Manager Unified Controller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.127.80.9%00
3.097.712.0%11