Junglewise Threat Intelligence

CVE-2021-47960: Synology SSL VPN Client information disclosure via local HTTP server

CVE-2021-47960 · Severity: medium · CVSS 6.5 · Published 2026-04-10

Vendors: Synology.

Executive brief

Synology SSL VPN Client is a tool used by employees to securely connect to their corporate network. A security flaw in this software allows a malicious website to trick the client into sharing sensitive files from the user's computer, such as configuration data, digital certificates, and logs. If exploited, this could lead to the theft of credentials or other information that helps an attacker gain unauthorized access to the company's internal network.

Technical details

A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in the Synology SSL VPN Client. The application runs a local HTTP server bound to the loopback interface (127.0.0.1) which does not properly restrict access to the installation directory. A remote attacker can exploit this by enticing a user to visit a specially crafted webpage; the webpage can then make requests to the local loopback service to retrieve sensitive files, including configuration files, certificates, and logs. This results in information disclosure that could facilitate further attacks. The issue is resolved in version 1.4.5-0684.

Affected products

  • Synology SSL VPN Client before 1.4.5-0684

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: patched: Fixed in version 1.4.5-0684
  • 2026-04-10: advisory

References

Related threats