PT-2024-9668 · Synology · Synology Router Manager

Published

2024-09-09

·

Updated

2025-08-01

·

CVE-2024-53281

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Synology Router Manager versions prior to 1.3.1-9346-10
Description The issue is related to improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS), in the Network WOL functionality. This could allow a remote attacker to inject arbitrary web script or HTML, potentially leading to security breaches. The vulnerability is exploited by injecting malicious scripts via unspecified vectors, affecting the structure of web pages.
Recommendations For versions prior to 1.3.1-9346-10, update to version 1.3.1-9346-10 or later to resolve the issue. As a temporary workaround, consider restricting access to the Network WOL functionality until a patch is applied. Avoid using the vulnerable Network WOL feature in Synology Router Manager until the update is installed.

Fix

DoS

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-11380
CVE-2024-53281

Affected Products

Synology Router Manager