Impact
The vulnerability is an SQL injection in the Sharing API of Synology DiskStation Manager, where special characters are not properly neutralized in SQL commands. Attackers who are authenticated can craft API requests that cause the backend database to return the contents of any file that is shared, effectively allowing them to read arbitrary files on the device. The weakness is a classic input handling flaw (CWE‑89).
Affected Systems
Synology DiskStation Manager installations running any of the versions listed as vulnerable: any pre‑7.2.1 builds before build 69057‑10, any 7.2.2 builds before build 72806‑7, and any 7.3.2 builds before build 86009‑2. All affected DSM deployments using the standard Sharing API are implicated.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate impact focused on data confidentiality. The EPSS score indicates a very low probability of exploitation at present, and the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation still requires the attacker to be an authenticated user, but once authenticated, they can retrieve arbitrary files through simple API calls, making the attack straightforward for privileged users or attackers who have compromised credentials. Overall, the risk is moderate, with a clear path to data exposure rather than code execution or denial of service.
OpenCVE Enrichment