Executive brief
Synology DiskStation Manager (DSM), the operating system for Synology storage devices, contains a security flaw in its Single Sign-On (SSO) component. This vulnerability allows an unauthorized person to bypass login security and gain access to the system if they know certain technical identifiers (distinguished names) of valid users. Successful exploitation could lead to full system compromise, data theft, or unauthorized administrative control over the storage server.
Technical details
An authentication bypass vulnerability exists in the Single Sign-On (SSO) implementation of Synology DiskStation Manager (DSM). The flaw is categorized as an improper check for unusual or exceptional conditions (CWE-754). A remote, unauthenticated attacker can bypass security controls if they have prior knowledge of a user's Distinguished Name (DN). While the attack complexity is rated as high—likely due to the requirement of knowing specific internal directory identifiers—a successful exploit allows for complete compromise of confidentiality, integrity, and availability. The issue is resolved in DSM versions 7.2.2-72806-5 and 7.3.1-86003-1.
Affected products
- Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected)
Timeline
- 2025-11-19: patched: Initial security update released
- 2026-05-27: disclosed: Vulnerability details and CVE published