Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors.
2024-03-28T07:16:12.177
2025-08-12T17:34:11.550
Analyzed
CVSSv3.1: 9.9 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | surveillance_station | < 9.2.0-9289 | Yes |
| Operating System | synology | diskstation_manager | 6.2 | No |
| Application | synology | surveillance_station | < 9.2.0-11289 | Yes |
| Operating System | synology | diskstation_manager | 7.1 | No |
| Operating System | synology | diskstation_manager | 7.2 | No |