PT-2024-28463 · Synology · Synology Router Manager

Sharon Brizinov

+1

·

Published

2024-06-28

·

Updated

2025-08-07

·

CVE-2024-39347

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology Router Manager versions prior to 1.2.5-8227-11 Synology Router Manager versions prior to 1.3.1-9346-8
Description The issue is related to incorrect default permissions in the firewall functionality, allowing man-in-the-middle attackers to access sensitive intranet resources. This is also described as an improper access control firewall bypass vulnerability.
Recommendations For versions prior to 1.2.5-8227-11, update to version 1.2.5-8227-11 or later. For versions prior to 1.3.1-9346-8, update to version 1.3.1-9346-8 or later.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-39347
ZDI-24-832

Affected Products

Synology Router Manager