CVE-2024-11398
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Dec 4, 2024
CWE ID 22
Summary
CVE-2024-11398 is a path traversal vulnerability affecting Synology Router Manager (SRM) versions prior to 1.3.1-9346-9. This issue grants remote authenticated users the ability to delete arbitrary files through unspecified vectors within the OTP reset functionality. The vulnerability arises from an improper limitation of a pathname to a restricted directory. This weakness could potentially be exploited to gain unintended access or disrupt system operations. It is recommended that affected users upgrade to the latest version of SRM to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Router Manager