Synology Router Manager (SRM)
by Synology
CVEs (44)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-29845 | Med | 0.28 | 4.3 | 0.00 | Dec 4, 2025 | A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files. | ||
| CVE-2025-29844 | Med | 0.28 | 4.3 | 0.00 | Dec 4, 2025 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. | ||
| CVE-2018-13292 | Med | 0.28 | 4.3 | 0.01 | Apr 1, 2019 | Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration. | ||
| CVE-2018-13290 | Med | 0.28 | 4.3 | 0.01 | Apr 1, 2019 | Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter. |
- risk 0.28cvss 4.3epss 0.00
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
- risk 0.28cvss 4.3epss 0.00
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
- risk 0.28cvss 4.3epss 0.01
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.
- risk 0.28cvss 4.3epss 0.01
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.
Page 3 of 3