Executive brief
Synology DiskStation Manager (DSM) is a network storage operating system that manages file access and user authentication on NAS devices. An insufficient entropy flaw in the login logic allows remote attackers without credentials to read or write arbitrary files and disrupt service availability. This exposes sensitive data and enables attackers to compromise the entire NAS device.
Technical details
This vulnerability is a CWE-331 (Insufficient Entropy) flaw in DSM's login logic that allows remote attackers to bypass authentication without credentials. The weak entropy in login mechanisms enables an attacker to predict or brute-force authentication tokens or session identifiers. No user interaction or authentication is required; the attack is performed remotely over the network. Successful exploitation allows attackers to achieve confidentiality, integrity, and availability impacts: reading arbitrary files, modifying stored data, and denying service. Patches are available in DSM 7.2.1-69057-12 or later, 7.2.2-72806-9 or later, 7.3.2-86009-4 or later, and 7.4-90075 or later.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-12, 7.2.2 before 7.2.2-72806-9, 7.3 before 7.3.2-86009-4, 7.4 before 7.4-90075
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Multiple patch releases published across DSM version branches