Impact
An improper limitation of a pathname to a restricted directory in the Audio API of Synology DiskStation Manager can allow a remote authenticated user to read non‑sensitive information from the server. The flaw is a classic path traversal weakness (CWE‑22) that does not provide escalation or malicious code execution, but it does expose data that should be protected from unauthenticated access.
Affected Systems
Synology DiskStation Manager (DSM) versions prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2 are affected. The vulnerability is located in the Audio API component of these firmware releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity; the EPSS score of less than 1% suggests a very low probability of real‑world exploitation. The flaw requires remote authentication, so an attacker must already have valid credentials, but the impact remains limited to non‑sensitive information disclosure. This vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment