Description
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote file read/write and denial of service
Action: Patch
AI Analysis

Impact

The flaw is identified as an insufficient entropy weakness (CWE-331). Synology DiskStation Manager versions prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 contain an insufficient entropy bug in their login authentication logic. Based on the description, it is inferred that the predictable login tokens could be exploited to read or write arbitrary files on the device. In addition, based on the description, it is inferred that the vulnerability could lead to denial-of-service attacks by corrupting critical resources or exhausting system capacity.

Affected Systems

Devices running Synology DiskStation Manager before the stated firmware releases are affected. This includes any Synology NAS units that have not migrated to a newer firmware revision containing the fix.

Risk and Exploitability

The CVSS score of 9.8 classifies the flaw as critical. The EPSS score of less than 1% indicates that exploit activity is currently very low. The vulnerability is not listed in the CISA KEV catalog and no public exploits are documented. Based on the description, it is inferred that attacks would be carried out by remote attackers exploiting predictable login tokens. While the likelihood of exploitation remains low, the high severity and potential for widespread impact necessitate prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 20:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest Synology DSM firmware that includes the login entropy fix
  • Configure the device firewall to block unauthorized remote access ports for DSM until the patch is applied
  • Monitor system logs for authentication anomalies and enforce strong administrator passwords to reduce brute‑force risks

Generated by OpenCVE AI on September 19, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Insufficient Entropy in DSM Login Enables Remote File Access and Denial of Service

Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Insufficient Entropy in DSM Login Enables Remote File Access and Denial of Service

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Weaknesses CWE-331
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:13:24.287Z

Reserved: 2026-06-29T09:59:06.873Z

Link: CVE-2026-13639

cve-icon Vulnrichment

Updated: 2026-09-18T19:13:18.633Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:38.757

Modified: 2026-09-18T20:17:06.860

Link: CVE-2026-13639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses