Impact
An improper encoding or escaping of output has been discovered in the Auth API of Synology DiskStation Manager (DSM). This weakness, classified as CWE-116, permits remote attackers to retrieve non‑sensitive information. The flaw is directly triggered when an attacker calls the Auth API, which can expose user or system data that should not be publicly available. The impact is limited to information disclosure and does not result in code execution or privilege escalation.
Affected Systems
The vulnerability exists in Synology DiskStation Manager releases prior to the following firmware revisions: 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4 and 7.4‑90075. In other words, any DSM system running a version older than these specific builds is susceptible. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low. The vulnerability is not recorded in the CISA KEV catalog, meaning that, so far, no known exploits have been publicly observed. The attack vector is inferred to be remote, as the flaw is triggered via a publicly reachable API. Exploitation requires access to the Auth API endpoint and may be facilitated by network connectivity to the DSM device.
OpenCVE Enrichment