Description
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote file read/write and denial of service
Action: Immediate patch
AI Analysis

Impact

An improper encoding or escaping flaw in SCGI within Synology DiskStation Manager allows attackers to manipulate responses that result in arbitrary file reads or writes. By exploiting this weakness, unauthorized remote users can access sensitive files or modify system files, leading to confidentiality or integrity violations, and can trigger denial‑of‑service attacks by disrupting the SCGI service.

Affected Systems

Synology DiskStation Manager (DSM) versions prior to 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4, and 7.4‑90075 are affected. Firmware upgrades to the listed versions or later mitigate the vulnerability.

Risk and Exploitability

With a CVSS score of 9.8, the flaw is considered critical. The EPSS score below 1 % indicates a low overall likelihood of exploitation in the near term, and it is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely by sending crafted SCGI requests to the DSM instance. The ability to read or write arbitrary files presents a high risk to confidentiality, integrity, and availability, even though exploitation attempts are currently infrequent.

Generated by OpenCVE AI on September 19, 2026 at 20:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update DSM to at least version 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4, or 7.4‑90075, or any newer release that incorporates the fix.
  • Disable or restrict the SCGI service to trusted networks, or block inbound SCGI traffic if the service is not required.
  • Implement firewall rules to limit exposure of the DSM management interface to only necessary IP addresses.

Generated by OpenCVE AI on September 19, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Encoding in SCGI Allows Remote File Read/Write and DoS in Synology DSM

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks.
Weaknesses CWE-116
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:14:16.588Z

Reserved: 2026-06-29T10:42:15.926Z

Link: CVE-2026-13684

cve-icon Vulnrichment

Updated: 2026-09-18T19:14:11.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:39.237

Modified: 2026-09-18T20:17:08.373

Link: CVE-2026-13684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:56Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output