CVE-2021-26562

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Feb 26, 2021
Updated: Jan 14, 2025
CWE ID 787

Summary

CVE-2021-26562 is a serious out-of-bounds write vulnerability affecting Synology DiskStation Manager (DSM) versions prior to 6.2.3-25426-3. This issue enables man-in-the-middle attackers to exploit the synoagentregisterd component, resulting in arbitrary code execution via a specially crafted syno_finder_site HTTP header. Successful exploitation can compromise the affected system, potentially leading to data theft or unauthorized system access. It is recommended that Synology users upgrade to the latest DSM version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DiskStation Manager
  • Synology Diskstation Manager Unified Controller

Affected Vendors

  • Synology