Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.
References
| Link | Resource |
|---|---|
| https://www.synology.com/en-global/security/advisory/Synology_SA_23_16 | Vendor Advisory |
| https://www.synology.com/en-global/security/advisory/Synology_SA_23_16 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-06-28 07:15
Updated : 2025-08-07 13:46
NVD link : CVE-2024-39347
Mitre link : CVE-2024-39347
CVE.ORG link : CVE-2024-39347
JSON object : View
Products Affected
synology
- router_manager
CWE
CWE-276
Incorrect Default Permissions
