Executive brief
Synology Surveillance Station is a professional video management system used to manage IP cameras and security recordings. A security flaw in the AddOns feature allows an authenticated user with administrator-level privileges to access sensitive information they should not be authorized to see. While this requires an existing account with high privileges, it could lead to further unauthorized access or data exposure within the surveillance environment.
Technical details
A missing authorization vulnerability (CWE-862) exists within the AddOns functionality of Synology Surveillance Station. The flaw allows a remote authenticated attacker with high privileges (administrator) to bypass intended access controls and retrieve sensitive information via unspecified vectors. The vulnerability is present in versions prior to 9.2.2-11575 (for DSM 7.x) and 9.2.2-9575 (for DSM 6.2). Exploitation does not require user interaction but does require valid administrative credentials. Synology has released patches to address this issue in the affected versions.
Affected products
- Synology Surveillance Station for DSM 7.2 before 9.2.2-11575
- Synology Surveillance Station for DSM 7.1 before 9.2.2-11575
- Synology Surveillance Station for DSM 6.2 before 9.2.2-9575
Timeline
- 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
- 2026-05-27: disclosed: Detailed vulnerability information disclosed
- 2026-05-27: patched: Fixed in versions 9.2.2-11575 and 9.2.2-9575