important · Firmware / Edge
Unauthenticated network clients can read or write arbitrary files on current Synology DSM branches.
Affects
Synology DiskStation Manager, the embedded operating system and management environment for Synology NAS appliances.
The attacker must reach the affected SCGI or login path, but we do not know its default exposure, service privilege, writable paths or whether file write composes into execution.
Detail and 2 sources
Synology provides fixed current branches, but affected end-of-life hardware is outside their reach.
Chain to watch
Reach an affected DSM SCGI or login path→↓Obtain unauthenticated arbitrary file access→↓Determine whether a privileged writable path yields execution→↓Writable paths, process identity and the file-write-to-execution step are unknown.
Unverified chainTest a stock NAS to identify reachable endpoints, writable paths and service identities.