Router Manager

Vendor:

First CVE: Aug 28, 2017 · Active for 8 years

59
Total CVEs
More Total CVEs than 99% of tracked products
8.4
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Router Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 28, 2017
8 years ago
Most Recent CVE
Dec 4, 2025
236 days ago

CVE Severity & Scoring

Router Manager59 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local2 (3.4%)
Network55 (93.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.4%)
Attack Complexity
Low46 (78.0%)
High13 (22.0%)
Unknown0 (0.0%)
User Interaction
None45 (76.3%)
Unknown0 (0.0%)
Required14 (23.7%)
Privileges Required
Low17 (28.8%)
High13 (22.0%)
None29 (49.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (59 CVEs).

59 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attac
Dec 20, 20189.884NOYES
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side
Jan 4, 20185.683NOYES
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7
Oct 29, 20209.831NONO
Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.
Oct 29, 202010.029NONO
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is tr
Feb 3, 20208.829NONO
Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to overflow buffers via
Jan 5, 20239.828NONO
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp an
Mar 6, 20187.528NONO
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain se
Oct 29, 20209.027NONO
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a
Mar 6, 20187.527NONO

Exploit Exposure

Signals from CVEs in this product scope (59 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
5.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (59 CVEs).

Media Mentions

Signals from CVEs in this product scope (59 CVEs).

Top CNAs Publishing CVEs For Router Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.3.1-9346196.10.4%00
1.2.5-822726.70.4%00
1.277.62.4%00
1.128.746.8%01