PT-2020-16749 · Synology · Synology Router Manager

Published

2020-10-29

·

Updated

2022-11-16

·

CVE-2020-27655

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology Router Manager (SRM) versions prior to 1.2.4-8081
Description The issue is related to improper access control, allowing remote attackers to access restricted resources via inbound QuickConnect traffic. This can be exploited by attackers to gain unauthorized access.
Recommendations For Synology Router Manager (SRM) versions prior to 1.2.4-8081, update to version 1.2.4-8081 or later to resolve the issue. As a temporary workaround, consider restricting inbound QuickConnect traffic to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2020-27655

Affected Products

Synology Router Manager