Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
2022-03-25T07:15:07.673
2025-01-14T19:29:55.853
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | synology | diskstation_manager | < 7.0.1-42214 | Yes |
Operating System | synology | diskstation_manager | < 6.2.4-25556-2 | Yes |