Description
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.
Published: 2026-09-18
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Access and Denial of Service via CRLF Injection
Action: Patch Immediately
AI Analysis

Impact

An improper neutralization of CRLF sequences in the User API of Synology DiskStation Manager allows an attacker with legitimate credentials to perform CRLF injection. This enables the attacker to read from or write to arbitrary files on the system, and can trigger a denial‑of‑service condition after the device is rebooted. The weakness is classified as CWE‑93, which represents improper or missing neutralization of CRLF sequences.

Affected Systems

The vulnerability affects Synology DiskStation Manager before versions 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Any DSM installation running these builds is susceptible; newer releases incorporate the fix.

Risk and Exploitability

The CVSS score of 8 indicates a high severity. The EPSS score is less than 1 %, suggesting that at the time of analysis exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the DSM User API, likely over a network connection, and to construct a crafted API request that injects CRLF sequences to manipulate file paths or headers. Once the attack succeeds, the attacker can read or corrupt files and, after a reboot, cause a denial of service by triggering file‑system corruption or lockout.

Generated by OpenCVE AI on September 19, 2026 at 20:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Synology update that fixes versions 7.2.1‑69057‑10, 7.2.2‑72806‑7 or 7.3.2‑86009‑2 to the latest DSM release.
  • Restrict access to the User API by limiting administrative privileges and ensuring only trusted hosts can reach the API endpoints.
  • If an immediate patch is not feasible, disable or monitor the vulnerable API features and segregate the device from untrusted networks to reduce the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title CRLF Injection in Synology DSM User API Enables Remote File Access and DoS

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title CRLF Injection in Synology DSM User API Enables Remote File Access and DoS

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T10:49:40.037Z

Reserved: 2026-04-14T01:01:14.606Z

Link: CVE-2026-40530

cve-icon Vulnrichment

Updated: 2026-09-18T10:49:32.555Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:40.237

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')