High severity8.8NVD Advisory· Published Mar 25, 2022· Updated Jun 17, 2026
CVE-2022-22688
CVE-2022-22688
Description
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:*range: >=7.0,<7.0.1-42214
- cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*range: >=6.2,<6.2.4-25556-2
- (no CPE)range: <6.2.4-25556
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
1- www.synology.com/security/advisory/Synology_SA_21_22nvdVendor Advisory
News mentions
0No linked articles in our index yet.