CVE-2024-11398

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Dec 4, 2024
CWE ID 22

Summary

CVE-2024-11398 is a path traversal vulnerability affecting Synology Router Manager (SRM) versions prior to 1.3.1-9346-9. This issue grants remote authenticated users the ability to delete arbitrary files through unspecified vectors within the OTP reset functionality. The vulnerability arises from an improper limitation of a pathname to a restricted directory. This weakness could potentially be exploited to gain unintended access or disrupt system operations. It is recommended that affected users upgrade to the latest version of SRM to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share