Executive brief
Synology Note Station Client, a desktop application used for managing and syncing notes with Synology NAS devices, is vulnerable to credential theft. An attacker positioned on the same network as a user could intercept login information because the application transmits sensitive data without encryption. This could lead to unauthorized access to the user's private notes and potentially other data stored on their Synology device.
Technical details
A cleartext transmission vulnerability (CWE-319) exists in the Synology Note Station Client prior to version 2.2.4-703. The application fails to properly encrypt sensitive data during transmission, allowing an attacker with man-in-the-middle (MitM) capabilities to intercept and read user credentials in plain text. While the attack requires the adversary to be positioned between the client and the server (high attack complexity), no prior authentication or user interaction is required to exploit the flaw. Users should update to version 2.2.4-703 or later to remediate this issue.
Affected products
- Synology Note Station Client before 2.2.4-703
Timeline
- 2026-06-03: advisory: NVD publication date