PT-2023-28082 · Synology · Synology Router Manager

Mika Kulmala

·

Published

2023-08-31

·

Updated

2023-09-07

·

CVE-2023-41741

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology Router Manager (SRM) versions prior to 1.3.1-9346-6
Description The issue allows remote attackers to obtain sensitive information via unspecified vectors. This is related to the exposure of sensitive information to an unauthorized actor vulnerability in the cgi component.
Recommendations For Synology Router Manager (SRM) versions prior to 1.3.1-9346-6, update to version 1.3.1-9346-6 or later to resolve the issue. As a temporary workaround, consider restricting access to the cgi component to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2023-41741
ZDI-23-1342

Affected Products

Synology Router Manager