Junglewise Threat Intelligence

CVE-2024-47269: Synology Surveillance Station cleartext transmission in Export Key functionality

CVE-2024-47269 · Severity: medium · CVSS 4.9 · Published 2026-05-27

Technologies: Synology Surveillance Station. Vendors: Synology.

Executive brief

Synology Surveillance Station, a video management system used for security camera monitoring, contains a vulnerability in its key export feature. This flaw allows an authenticated administrator to transmit sensitive information over the network without encryption. If intercepted, this could lead to the exposure of sensitive security keys or configuration data, potentially compromising the integrity of the surveillance environment.

Technical details

A cleartext transmission of sensitive information vulnerability (CWE-319) exists in the Export Key functionality of Synology Surveillance Station. The flaw is located in the way the application handles sensitive data during export operations, failing to utilize encrypted channels for transmission. An attacker must be a remote authenticated user with administrator-level privileges to exploit this vulnerability. Successful exploitation allows the attacker to obtain sensitive information via unspecified vectors. The issue is resolved in versions 9.2.2-11575 (for DSM 7.1/7.2) and 9.2.2-9575 (for DSM 6.2).

Affected products

  • Synology Surveillance Station for DSM 7.2 before 9.2.2-11575
  • Synology Surveillance Station for DSM 7.1 before 9.2.2-11575
  • Synology Surveillance Station for DSM 6.2 before 9.2.2-9575

Timeline

  • 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
  • 2026-05-27: disclosed: Vulnerability details disclosed and CVE published to NVD

References

Related threats