VYPR
High severity8.8NVD Advisory· Published Mar 25, 2022· Updated Jun 17, 2026

CVE-2022-22688

CVE-2022-22688

Description

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:*range: >=7.0,<7.0.1-42214
    • cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*range: >=6.2,<6.2.4-25556-2
    • (no CPE)range: <6.2.4-25556
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.