Executive brief
Synology SSL VPN Client is a software utility used to establish secure remote connections to corporate networks. A security flaw in this client allows an attacker to access or modify a user's PIN code because it is stored insecurely in plain text. If a user visits a malicious website, the attacker could potentially reconfigure the VPN settings or intercept the user's network traffic, compromising private data and secure communications.
Technical details
A plaintext storage of a password vulnerability (CWE-256) exists in the Synology SSL VPN Client prior to version 1.4.5-0684. The application stores sensitive credentials, specifically the user's PIN code, in an insecure unencrypted format. A remote attacker can exploit this by inducing a user to interact with a crafted web page, which then leverages the client's local services to access or manipulate the stored PIN. Successful exploitation allows the attacker to modify VPN configurations or intercept subsequent VPN traffic. The vulnerability is addressed in version 1.4.5-0684.
Affected products
- Synology SSL VPN Client before 1.4.5-0684
Timeline
- 2026-04-10: disclosed: Initial public release of Synology advisory SA_26_05
- 2026-04-10: patched: Fixed in version 1.4.5-0684