Executive brief
Synology Surveillance Station, a video management system used for managing IP cameras and security footage, contains a vulnerability in its IPSpeaker component. This flaw allows an authenticated user with administrator-level privileges to access sensitive credentials that are not properly protected. An exploit could lead to the exposure of account information, potentially allowing further unauthorized access to connected security hardware or network services.
Technical details
An insufficiently protected credentials vulnerability (CWE-522) exists in the IPSpeaker component of Synology Surveillance Station. The flaw allows a remote authenticated attacker with high privileges (administrator) to retrieve sensitive information, likely due to improper storage or transmission of credentials within the IPSpeaker functionality. The attack vector is network-based and requires no user interaction, though it is limited to users who already possess administrative access. Successful exploitation results in a loss of confidentiality for stored credentials. The issue is resolved in Surveillance Station versions 9.2.2-11575 (for DSM 7.1/7.2) and 9.2.2-9575 (for DSM 6.2).
Affected products
- Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575
Timeline
- 2024-11-26: advisory: Initial public release of Synology SA_24_25
- 2026-05-27: disclosed: Detailed vulnerability information disclosed and CVE published to NVD