Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.
2018-07-13T20:29:00.753
2024-11-21T02:56:20.663
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | synology | ds107_firmware | ≤ 3.1-1639 | Yes |
| Hardware | synology | ds107 | - | No |
| Operating System | synology | ds213_firmware | ≤ 5.2-5644-1 | Yes |
| Hardware | synology | ds213 | - | No |
| Operating System | synology | ds116_firmware | ≤ 5.2-5644-1 | Yes |
| Hardware | synology | ds116 | - | No |