High severity8.1NVD Advisory· Published May 16, 2023· Updated Jun 17, 2026
CVE-2023-32955
CVE-2023-32955
Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DHCP Client Functionality in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows man-in-the-middle attackers to execute arbitrary commands via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:*range: >=1.2,<1.2.5-8227-6
- (no CPE)range: <1.2.5-8227-6, <1.3.1-9346-3
- Range: 1.2
Patches
Vulnerability mechanics
References
1- www.synology.com/en-global/security/advisory/Synology_SA_22_25nvdVendor Advisory
News mentions
0No linked articles in our index yet.