Impact
The vulnerability is an external control of file name or path in the Upload API of Synology DiskStation Manager. Remote authenticated users can specify arbitrary file names or paths and write files to the system. They may create or overwrite any file that the DSM process can access, leading to denial of service by corrupting critical system files.
Affected Systems
Synology DiskStation Manager devices running firmware versions before DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 or 7.4-90075 are vulnerable. Any Synology NAS operating those firmware releases is affected.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated to the DSM system; therefore, the likely attack vector involves a compromised or malicious legitimate user account. Once authenticated, the attacker can exploit the upload feature to write arbitrary files and cause a denial‑of‑service by corrupting essential system files.
OpenCVE Enrichment