Junglewise Threat Intelligence

CVE-2024-47272: Synology Surveillance Station incorrect authorization in IO Module

CVE-2024-47272 · Severity: low · CVSS 2.7 · Published 2026-05-27

Technologies: Synology Surveillance Station. Vendors: Synology.

Executive brief

Synology Surveillance Station, a video management system used for managing IP cameras and security recordings, contains a vulnerability in its IO Module. An authenticated user with administrator privileges can perform unauthorized file writes to certain locations on the system. While this requires high-level access, it could allow an administrator to exceed their intended permissions and modify system files, potentially impacting the integrity of the surveillance environment.

Technical details

An incorrect authorization vulnerability (CWE-863) exists within the IO Module functionality of Synology Surveillance Station. The flaw allows a remote authenticated attacker with administrator-level privileges to perform limited file writes via unspecified vectors. The vulnerability is caused by insufficient permission checks when handling IO Module operations. This could lead to unauthorized modification of specific files on the underlying DiskStation Manager (DSM) host. The issue is resolved in Surveillance Station versions 9.2.2-11575 (for DSM 7.x) and 9.2.2-9575 (for DSM 6.2).

Affected products

  • Synology Surveillance Station for DSM 7.2 before 9.2.2-11575
  • Synology Surveillance Station for DSM 7.1 before 9.2.2-11575
  • Synology Surveillance Station for DSM 6.2 before 9.2.2-9575

Timeline

  • 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
  • 2026-05-27: disclosed: Vulnerability details disclosed and CVE published

References

Related threats