Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitrary files via unspecified vectors.
2023-01-05T10:15:09.990
2024-11-21T07:27:22.867
Modified
CVSSv3.1: 7.5 (HIGH)
-
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | router_manager | < 1.2.5-8227-6 | Yes |
| Application | synology | router_manager | < 1.3.1-9346-3 | Yes |