Impact
The vulnerability is an improper restriction of a pathname to a designated directory (CWE‑22) in the Desktop API of Synology DiskStation Manager. Remote attackers can write files to controlled directories and trigger limited denial‑of‑service conditions by overwriting or creating specific files. The impact does not extend to full malicious code execution but permits manipulation of file contents and potential service disruption.
Affected Systems
Synology DiskStation Manager (DSM) is affected in all releases prior to version 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Users running these earlier builds are at risk.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as moderate severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation. Synology has not listed the vulnerability in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote via the Desktop API over an open network interface. Exploitation requires network access to the DSM instance and the ability to construct a payload that includes a traversable path component. Successful exploitation allows limited file writes within the constrained directory, which could alter configuration files or trigger service failures, but does not grant full system compromise.
OpenCVE Enrichment