Executive brief
Synology Surveillance Station, a video management system for security cameras, contains a vulnerability in its Archiving Pull feature. An authorized administrator could potentially write files to unintended locations on the system. While this requires high-level access, it could allow for unauthorized modification of system files or configuration.
Technical details
A path traversal vulnerability (CWE-22) exists in the Archiving Pull functionality of Synology Surveillance Station. The flaw stems from improper limitation of pathnames to restricted directories, allowing an attacker to bypass intended directory constraints. A remote authenticated user with administrator privileges can exploit this via unspecified vectors to achieve limited file writes on the underlying filesystem. The vulnerability is addressed in versions 9.2.2-11575 (for DSM 7.1/7.2) and 9.2.2-9575 (for DSM 6.2).
Affected products
- Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575
Timeline
- 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
- 2026-05-27: disclosed: Detailed vulnerability information published