Impact
An improper neutralization of CRLF sequences in the User API of Synology DiskStation Manager allows an attacker with legitimate credentials to perform CRLF injection. This enables the attacker to read from or write to arbitrary files on the system, and can trigger a denial‑of‑service condition after the device is rebooted. The weakness is classified as CWE‑93, which represents improper or missing neutralization of CRLF sequences.
Affected Systems
The vulnerability affects Synology DiskStation Manager before versions 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Any DSM installation running these builds is susceptible; newer releases incorporate the fix.
Risk and Exploitability
The CVSS score of 8 indicates a high severity. The EPSS score is less than 1 %, suggesting that at the time of analysis exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the DSM User API, likely over a network connection, and to construct a crafted API request that injects CRLF sequences to manipulate file paths or headers. Once the attack succeeds, the attacker can read or corrupt files and, after a reboot, cause a denial of service by triggering file‑system corruption or lockout.
OpenCVE Enrichment