Junglewise Threat Intelligence

CVE-2025-13392: Synology DSM authentication bypass in SSO

CVE-2025-13392 · Severity: high · CVSS 8.1 · Published 2026-05-27

Technologies: Synology DiskStation Manager, Synology DiskStation Manager (DSM). Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM), the operating system for Synology storage devices, contains a security flaw in its Single Sign-On (SSO) component. This vulnerability allows an unauthorized person to bypass login security and gain access to the system if they know certain technical identifiers (distinguished names) of valid users. Successful exploitation could lead to full system compromise, data theft, or unauthorized administrative control over the storage server.

Technical details

An authentication bypass vulnerability exists in the Single Sign-On (SSO) implementation of Synology DiskStation Manager (DSM). The flaw is categorized as an improper check for unusual or exceptional conditions (CWE-754). A remote, unauthenticated attacker can bypass security controls if they have prior knowledge of a user's Distinguished Name (DN). While the attack complexity is rated as high—likely due to the requirement of knowing specific internal directory identifiers—a successful exploit allows for complete compromise of confidentiality, integrity, and availability. The issue is resolved in DSM versions 7.2.2-72806-5 and 7.3.1-86003-1.

Affected products

  • Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected)

Timeline

  • 2025-11-19: patched: Initial security update released
  • 2026-05-27: disclosed: Vulnerability details and CVE published

References

Related threats