PT-2025-11663 · Synology · Synology Drive Server

Published

2025-03-19

·

Updated

2026-05-30

·

CVE-2024-50631

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Synology Drive Server versions prior to 3.0.4-12699 Synology Drive Server versions prior to 3.2.1-23280 Synology Drive Server versions prior to 3.5.0-26085 Synology Drive Server versions prior to 3.5.1-26102
Description The issue is related to the improper neutralization of special elements used in an SQL command, also known as 'SQL Injection', in the system syncing daemon. This allows remote attackers to inject SQL commands, but these are limited to write operations. The attack vectors are not specified.
Recommendations For versions prior to 3.0.4-12699, update to version 3.0.4-12699 or later. For versions prior to 3.2.1-23280, update to version 3.2.1-23280 or later. For versions prior to 3.5.0-26085, update to version 3.5.0-26085 or later. For versions prior to 3.5.1-26102, update to version 3.5.1-26102 or later.

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-50631
ZDI-25-213

Affected Products

Synology Drive Server