Synology · Synology Router Manager · CVE-2024-53284
**Name of the Vulnerable Software and Affected Versions**
Synology Router Manager (SRM) versions prior to 1.3.1-9346-10
**Description**
The issue is related to improper neutralization of input during web page generation, also known as Cross-site Scripting, in the WiFi Connect Setting functionality. This allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.
**Recommendations**
For Synology Router Manager (SRM) versions prior to 1.3.1-9346-10, update to version 1.3.1-9346-10 or later to resolve the issue. As a temporary workaround, consider restricting access to the WiFi Connect Setting functionality to minimize the risk of exploitation.