Impact
A forced browsing vulnerability in the Wallpaper Path component of Synology DiskStation Manager allows an attacker who has authenticated remotely to send a direct request to a sensitive endpoint and obtain information that should be protected. The flaw is a classic path traversal/forced browsing issue that can expose confidential data stored under the wallpaper directory. This weakness is classified as CWE-425, indicating that the system fails to enforce proper authorization checks on the resource path.
Affected Systems
Synology DiskStation Manager versions prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2 are vulnerable. The issue specifically impacts the wallpaper management interface exposed by DSM on networked devices from Synology.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited or no evidence of active exploitation. Attackers would need valid DSM credentials to succeed, indicating that the threat surfaces only to authenticated users and relies on an authenticated session or credentials leakage.
OpenCVE Enrichment