Description
An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.
Published: 2026-09-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Read limited files via brute‑force authentication
Action: Apply Patch
AI Analysis

Impact

An improper restriction of excessive authentication attempts in the Auto Block feature of Synology DiskStation Manager allows remote attackers to repeatedly attempt to authenticate and then read a restricted set of files. The flaw does not permit arbitrary code execution; it is limited to reading files whose paths can be enumerated through successful brute‑force attempts. This information disclosure can compromise sensitive data stored on the device.

Affected Systems

Synology DiskStation Manager (DSM) versions earlier than 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2 are affected. The vulnerability exists in DSM releases prior to these revision numbers; newer releases incorporate the fix.

Risk and Exploitability

The CVSS score of 3.7 classifies this issue as low severity, and the EPSS score of less than 1% indicates a very low likelihood of widespread exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this weakness remotely over the network by launching brute‑force login attempts against the DSM Auto Block feature. Successful brute‑force attempts enable enumeration and reading of a small set of files, potentially revealing confidential information, but the impact is constrained by the limited file set.

Generated by OpenCVE AI on September 19, 2026 at 20:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DSM to version 7.2.1‑69057‑10, 7.2.2‑72806‑7, 7.3.2‑86009‑2, or later to address the authentication throttling flaw.
  • Disable or reduce the Auto Block threshold if configuration allows, to limit the number of rapid login attempts that can succeed.
  • Configure two‑factor authentication and enforce strong password policies to make brute‑force attacks more difficult.

Generated by OpenCVE AI on September 19, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Restriction of Excessive Authentication Attempts Enables Brute‑Force File Access in Synology DSM

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Improper Restriction of Excessive Authentication Attempts Enables Brute‑Force File Access in Synology DSM

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T10:42:50.358Z

Reserved: 2026-04-14T01:01:14.607Z

Link: CVE-2026-40538

cve-icon Vulnrichment

Updated: 2026-09-18T10:42:45.497Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:41.307

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts