VYPR

Router Manager

by Synology

CVEs (59)

  • CVE-2024-53282MedDec 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write…

  • CVE-2024-53281MedDec 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users to read or write specific files containing non-sensitive…

  • CVE-2024-53280MedDec 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write…

  • CVE-2024-53279MedDec 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files…

  • CVE-2024-39347MedJun 28, 2024
    risk 0.38cvss 5.9epss 0.01

    Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.

  • CVE-2023-2729MedJun 13, 2023
    risk 0.38cvss 5.9epss 0.01

    Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.

  • CVE-2020-27651MedOct 29, 2020
    risk 0.38cvss 5.8epss 0.01

    Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

  • CVE-2025-29843MedDec 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

  • CVE-2023-41741MedAug 31, 2023
    risk 0.35cvss 5.3epss 0.01

    Exposure of sensitive information to an unauthorized actor vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2023-41740MedAug 31, 2023
    risk 0.35cvss 5.3epss 0.01

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to read specific files via unspecified vectors.

  • CVE-2018-13289MedApr 1, 2019
    risk 0.35cvss 5.3epss 0.02

    Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.

  • CVE-2018-7170MedMar 6, 2018
    risk 0.35cvss 5.3epss 0.03

    ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists…

  • CVE-2023-41739MedAug 31, 2023
    risk 0.32cvss 4.9epss 0.01

    Uncontrolled resource consumption vulnerability in File Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors.

  • CVE-2017-12077MedAug 28, 2017
    risk 0.32cvss 4.9epss 0.01

    Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.

  • CVE-2025-29845MedDec 4, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.

  • CVE-2025-29844MedDec 4, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.

  • CVE-2018-13292MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.

  • CVE-2018-13290MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.

  • CVE-2019-9495LowApr 17, 2019
    risk 0.24cvss 3.7epss 0.03

    The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary…

Page 3 of 3