Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to execute arbitrary code via unspecified vectors.
2025-07-23T05:15:29.460
2025-07-29T19:34:07.740
Analyzed
CVSSv3.1: 7.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | synology | router_manager | < 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |