Impact
The vulnerability is an improper neutralization of CRLF sequences, also known as CRLF injection, in the Synology DiskStation Manager Sharing API. This flaw permits a remote authenticated user to craft a sharing URL that, when visited by a victim, causes the system to write a file to a limited set of directories. The primary impact is the ability to create or overwrite files on the affected device, which could lead to further compromise if additional privileged actions are possible.
Affected Systems
Synology DiskStation Manager (DSM) is affected. The flaw exists in versions released prior to 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4, and 7.4‑90075. Any DSM installation that has not been upgraded to one of these patch levels is vulnerable.
Risk and Exploitability
The CVSS score is 3.5, indicating low severity, and the EPSS score is less than 1 %, suggesting a very low probability of exploitation at the time of this analysis. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be authenticated to the DSM account, which then generates a malicious sharing URL. When a victim clicks that link, the system writes a file the attacker specifies, offering a limited attack surface but still posing risk to data integrity.
OpenCVE Enrichment