Description
Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.
Published: 2026-05-27
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Synology Surveillance Station versions before 9.2.2‑11575 and 9.2.2‑9575 contain a flaw in the Export Key feature that sends sensitive information in clear text. The bug, mapped to CWE‑319, allows remote authenticated users who have administrator privileges to read those exported keys during transmission. While the vulnerability does not grant arbitrary code execution, it can lead to disclosure of credentials or keys, potentially compromising the confidentiality of the system and its stored data.

Affected Systems

Synology Surveillance Station running versions earlier than 9.2.2‑11575 or 9.2.2‑9575 is affected. The flaw is present in the Export Key utility that is part of the Surveillance Station package. Only servers that have this older release installed are at risk; newer releases have no known such issue.

Risk and Exploitability

The CVSS score of 4.9 indicates a medium severity and the EPSS is not available. The vulnerability requires an authenticated administrator to exploit, so an attacker must have valid credentials and location to trigger the Export Key operation. Because the flaw transmits data over unsecured channels, once authenticated the attacker can retrieve the key payload, potentially enabling further credential compromise. The lack of data in KEV suggests no high‑profile exploitation yet, but the cleartext transmission can still be abused, especially if remote administration is permitted.

Generated by OpenCVE AI on May 27, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Synology Surveillance Station to version 9.2.2‑11575 or later, or to the latest stable release available.
  • Disable or restrict remote administrative access, allowing only local or VPN‑based management of the system.
  • Ensure all administrative communication uses encrypted channels (HTTPS/TLS or SSH tunnel) and reduce the number of administrator accounts to the minimum required.

Generated by OpenCVE AI on May 27, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology surveillance Station
Vendors & Products Synology
Synology surveillance Station

Wed, 27 May 2026 11:15:00 +0000

Type Values Removed Values Added
Title Cleartext Transmission of Sensitive Information via Export Key in Synology Surveillance Station

Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Synology Surveillance Station
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-05-27T08:29:47.032Z

Reserved: 2024-09-24T03:58:57.133Z

Link: CVE-2024-47269

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-27T09:16:25.740

Modified: 2026-05-27T09:16:25.740

Link: CVE-2024-47269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T12:30:25Z

Weaknesses