Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
2025-07-23T05:15:29.870
2025-07-29T19:33:38.310
Analyzed
CVSSv3.1: 5.9 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | synology | router_manager | < 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |
| Operating System | synology | router_manager | 1.3.1-9346 | Yes |