Junglewise Threat Intelligence

CVE-2024-47267: Synology Surveillance Station path traversal in Archiving Pull

CVE-2024-47267 · Severity: low · CVSS 2.7 · Published 2026-05-27

Technologies: Synology Surveillance Station. Vendors: Synology.

Executive brief

Synology Surveillance Station, a video management system for security cameras, contains a vulnerability in its Archiving Pull feature. An authorized administrator could potentially write files to unintended locations on the system. While this requires high-level access, it could allow for unauthorized modification of system files or configuration.

Technical details

A path traversal vulnerability (CWE-22) exists in the Archiving Pull functionality of Synology Surveillance Station. The flaw stems from improper limitation of pathnames to restricted directories, allowing an attacker to bypass intended directory constraints. A remote authenticated user with administrator privileges can exploit this via unspecified vectors to achieve limited file writes on the underlying filesystem. The vulnerability is addressed in versions 9.2.2-11575 (for DSM 7.1/7.2) and 9.2.2-9575 (for DSM 6.2).

Affected products

  • Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575

Timeline

  • 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
  • 2026-05-27: disclosed: Detailed vulnerability information published

References

Related threats