Description
Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.
Published: 2026-05-27
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Synology Surveillance Station includes an IO Module that manages file I/O operations. In versions prior to 9.2.2-11575 and 9.2.2-9575, the module contains an incorrect authorization check that permits remote authenticated users who already have administrator privileges to perform limited file write operations. This flaw is an example of improper authorization (CWE-863). An attacker who can authenticate as an administrator could modify configuration files or upload malicious files to the device, potentially disrupting service or facilitating further attack steps.

Affected Systems

The vulnerability affects Synology’s Surveillance Station software on devices running versions earlier than 9.2.2-11575 and 9.2.2-9575. Administrators with full control of the system can exploit the flaw. Systems that have not upgraded beyond these build numbers are at risk.

Risk and Exploitability

The CVSS base score of 2.7 indicates low severity, and the lack of publicly available EPSS data combined with its absence from the CISA KEV catalog suggests it is not currently being exploited in the wild. Exploitation requires a remote authenticated session with administrator rights; an attacker possessing such credentials, perhaps obtained through credential compromise or social engineering, could use the flaw to alter system files. Because the attack vector is limited to administrators, risk is confined to environments where privileged credentials are compromised.

Generated by OpenCVE AI on May 27, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Synology Surveillance Station update, at least version 9.2.2-11575, to patch the IO Module authorization flaw.
  • If an immediate update is not possible, restrict or disable the IO Module feature to prevent unintended file write operations, or enforce strict access controls on the affected directories.
  • Revoke or rotate any compromised administrator credentials and enforce multi‑factor authentication to limit the impact of credential compromise.

Generated by OpenCVE AI on May 27, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Synology diskstation Manager
CPEs cpe:2.3:a:synology:surveillance_station:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:6.2:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:7.2:*:*:*:*:*:*:*
Vendors & Products Synology diskstation Manager

Wed, 27 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:45:00 +0000

Type Values Removed Values Added
Title Synology Surveillance Station IO Module Authorization Flaw Allows Limited File Write
First Time appeared Synology
Synology surveillance Station
Vendors & Products Synology
Synology surveillance Station

Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Synology Diskstation Manager Surveillance Station
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-05-27T13:45:34.960Z

Reserved: 2024-09-24T03:58:57.133Z

Link: CVE-2024-47272

cve-icon Vulnrichment

Updated: 2026-05-27T13:45:30.335Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T09:16:26.100

Modified: 2026-05-28T18:37:15.180

Link: CVE-2024-47272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T10:30:28Z

Weaknesses