Executive brief
Synology Surveillance Station, a video management system used for managing IP cameras and security recordings, contains a vulnerability in its Archiving Push feature. This flaw allows a remote user who already has administrator-level access to write to certain files they should not normally be able to modify. While the impact is limited because it requires high-level permissions, it could potentially be used to bypass intended security restrictions or alter system configurations.
Technical details
An improper preservation of permissions vulnerability (CWE-281) exists in the Archiving Push functionality of Synology Surveillance Station. The flaw allows a remote authenticated attacker with administrator privileges to perform limited file writes via unspecified vectors. The vulnerability stems from the application failing to correctly maintain or enforce permission boundaries during archiving operations. This issue is resolved in Surveillance Station versions 9.2.2-11575 (for DSM 7.1/7.2) and 9.2.2-9575 (for DSM 6.2).
Affected products
- Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575
Timeline
- 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
- 2026-05-27: disclosed: Detailed vulnerability information disclosed and CVE published to NVD