Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.
2025-12-04T15:15:54.290
2025-12-05T21:44:21.507
Analyzed
CVSSv3.1: 9.6 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | synology | diskstation_manager | < 7.2.1-69057-2 | Yes |
| Operating System | synology | diskstation_manager | < 7.2.2-72806 | Yes |
| Operating System | synology | diskstation_manager_unified_controller | < 3.1.4-23079 | Yes |