Impact
The flaw is identified as an insufficient entropy weakness (CWE-331). Synology DiskStation Manager versions prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 contain an insufficient entropy bug in their login authentication logic. Based on the description, it is inferred that the predictable login tokens could be exploited to read or write arbitrary files on the device. In addition, based on the description, it is inferred that the vulnerability could lead to denial-of-service attacks by corrupting critical resources or exhausting system capacity.
Affected Systems
Devices running Synology DiskStation Manager before the stated firmware releases are affected. This includes any Synology NAS units that have not migrated to a newer firmware revision containing the fix.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical. The EPSS score of less than 1% indicates that exploit activity is currently very low. The vulnerability is not listed in the CISA KEV catalog and no public exploits are documented. Based on the description, it is inferred that attacks would be carried out by remote attackers exploiting predictable login tokens. While the likelihood of exploitation remains low, the high severity and potential for widespread impact necessitate prompt remediation.
OpenCVE Enrichment