Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
2024-12-04T07:15:05.983
2025-07-29T19:42:50.477
Analyzed
CVSSv3.1: 8.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | synology | router_manager | < 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |
Operating System | synology | router_manager | 1.3.1-9346 | Yes |