VendorsSynologyrouter_managerany version
Vulnerabilities

Synology Router Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2018-7170
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
Published 2018-03-06 · Modified
5.3EPSS 0.027
CVE-2018-13289
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.
Published 2019-04-01 · Modified
5.3EPSS 0.016
CVE-2023-41740
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to read specific files via unspecified vectors.
Published 2023-08-31 · Modified
5.3EPSS 0.008
CVE-2017-12077
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.
Published 2017-08-28 · Modified
4.9EPSS 0.014
CVE-2019-9495
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
Published 2019-04-17 · Modified
4.3EPSS 0.035
CVE-2018-13292
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.
Published 2019-04-01 · Modified
4.3EPSS 0.013
CVE-2018-13290
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.
Published 2019-04-01 · Modified
4.3EPSS 0.013
CVE-2025-29844
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
Published 2025-12-04 · Analyzed
4.3EPSS 0.004
CVE-2025-29845
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
Published 2025-12-04 · Analyzed
4.3EPSS 0.004
← Prev2 / 2