Executive brief
Synology Surveillance Station, a video management system used for managing IP cameras and security recordings, contains a vulnerability in its IO Module. An authenticated user with administrator privileges can perform unauthorized file writes to certain locations on the system. While this requires high-level access, it could allow an administrator to exceed their intended permissions and modify system files, potentially impacting the integrity of the surveillance environment.
Technical details
An incorrect authorization vulnerability (CWE-863) exists within the IO Module functionality of Synology Surveillance Station. The flaw allows a remote authenticated attacker with administrator-level privileges to perform limited file writes via unspecified vectors. The vulnerability is caused by insufficient permission checks when handling IO Module operations. This could lead to unauthorized modification of specific files on the underlying DiskStation Manager (DSM) host. The issue is resolved in Surveillance Station versions 9.2.2-11575 (for DSM 7.x) and 9.2.2-9575 (for DSM 6.2).
Affected products
- Synology Surveillance Station for DSM 7.2 before 9.2.2-11575
- Synology Surveillance Station for DSM 7.1 before 9.2.2-11575
- Synology Surveillance Station for DSM 6.2 before 9.2.2-9575
Timeline
- 2024-11-26: advisory: Initial public release of Synology advisory SA_24_25
- 2026-05-27: disclosed: Vulnerability details disclosed and CVE published