CVE-2022-27616
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Aug 3, 2022
Updated: Jan 14, 2025
CWE ID 78
Summary
CVE-2022-27616 is a vulnerability affecting Synology DiskStation Manager (DSM) before version 7.0.1-42218-3. This issue permits remote, authenticated users to execute arbitrary OS commands through the webapi component, due to inadequate neutralization of special elements. The exact attack vectors are unspecified, but successful exploitation could lead to significant security risks. Users are advised to update their DSM installations to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DiskStation Manager
Affected Vendors
- Synology