Description
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL.
Published: 2026-09-18
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated File Write
Action: Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of CRLF sequences, also known as CRLF injection, in the Synology DiskStation Manager Sharing API. This flaw permits a remote authenticated user to craft a sharing URL that, when visited by a victim, causes the system to write a file to a limited set of directories. The primary impact is the ability to create or overwrite files on the affected device, which could lead to further compromise if additional privileged actions are possible.

Affected Systems

Synology DiskStation Manager (DSM) is affected. The flaw exists in versions released prior to 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4, and 7.4‑90075. Any DSM installation that has not been upgraded to one of these patch levels is vulnerable.

Risk and Exploitability

The CVSS score is 3.5, indicating low severity, and the EPSS score is less than 1 %, suggesting a very low probability of exploitation at the time of this analysis. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be authenticated to the DSM account, which then generates a malicious sharing URL. When a victim clicks that link, the system writes a file the attacker specifies, offering a limited attack surface but still posing risk to data integrity.

Generated by OpenCVE AI on September 19, 2026 at 20:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest DSM update that contains the patch (DSM 7.2.1‑69057‑12 or later).
  • If sharing URLs are not required, disable the Sharing API or restrict its use to trusted users only.
  • Configure the DSM web interface to use HTTPS exclusively and consider limiting remote access to authenticated users.

Generated by OpenCVE AI on September 19, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title CRLF Injection in DiskStation Manager Sharing API Allows Authenticated File Write

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title CRLF Injection in DiskStation Manager Sharing API Allows Authenticated File Write

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL.
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:11:08.435Z

Reserved: 2026-06-29T10:30:40.284Z

Link: CVE-2026-13666

cve-icon Vulnrichment

Updated: 2026-09-18T19:10:55.897Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:38.877

Modified: 2026-09-18T20:17:07.373

Link: CVE-2026-13666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')