Executive brief
DiskStation Manager (DSM) is a web-based operating system that manages Synology NAS devices and controls file sharing, user access, and system operations. A CRLF injection vulnerability in the User API allows authenticated users to read or write arbitrary files and cause denial-of-service attacks after system reboot, potentially compromising data integrity and system availability.
Technical details
The vulnerability is an improper neutralization of CRLF sequences (CWE-93) in the User API component of Synology DSM. The flaw allows remote authenticated users to inject carriage return and line feed characters to manipulate system behavior, enabling arbitrary file read/write and denial-of-service attacks that persist after system reboot. The attack requires authentication and user interaction (per CVSS vector: AV:N/AC:L/PR:L/UI:R). The vulnerability has been patched in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later versions.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2
Timeline
- 2026-04-15: disclosed: Synology advisory SA_26_06 published
- 2026-09-18: patched: Patches available in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2
- 2026-09-18: advisory