VYPR
Low severity2.7NVD Advisory· Published May 27, 2026

CVE-2024-47267

CVE-2024-47267

Description

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A path traversal vulnerability in Synology Surveillance Station Archiving allows remote admin users limited file write within restricted directories.

Vulnerability

A path traversal vulnerability exists in the Archiving functionality of Synology Surveillance Station. The bug is an improper limitation of a pathname to a restricted directory, enabling limited file write by remote authenticated users with administrator privileges. Affected versions are Surveillance Station before 9.2.2-11575 on DSM 7.2 and 7.1, and before 9.2.2-9575 on DSM 6.2 [1].

Exploitation

An attacker must have remote network access and valid administrator credentials on the Synology Surveillance Station. The exact attack vector is unspecified, but the path traversal occurs in the Archiving Pull capability. With administrator-level access, the attacker can send crafted requests that cause file writes to unintended locations inside or near the restricted archive directory. The limited nature of the file write prevents full control over arbitrary paths [1].

Impact

Successful exploitation allows the attacker to perform limited file write operations outside the intended archive directory. The severity is low (CVSS 2.7) and the impact is constrained to writing specific files within a restricted scope, likely not leading to full compromise [1].

Mitigation

Synology released fixed versions: upgrade Surveillance Station to 9.2.2-11575 for DSM 7.2/7.1, and to 9.2.2-9575 for DSM 6.2. No workaround is disclosed, and the advisory provides no further mitigation steps [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.