Junglewise Threat Intelligence

CVE-2026-40538: Synology DiskStation Manager brute-force attack via insufficient rate limiting

CVE-2026-40538 · Severity: low · CVSS 3.7 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is the operating system for Synology NAS devices, which are commonly used in businesses for data storage and backup. An insufficiently protected login mechanism allows attackers to conduct brute-force attacks without proper rate limiting, potentially enabling unauthorized access to stored data and system configuration. This vulnerability affects DSM versions 7.2.1, 7.2.2, and 7.3.2 before specific patch levels.

Technical details

This vulnerability (CWE-307) involves improper restriction of excessive authentication attempts in the Auto block mechanism of Synology DSM. The vulnerability allows remote attackers to conduct brute-force attacks against login credentials with insufficient account lockout or rate-limiting protection. The attack requires no authentication and can be performed over the network, though with moderate complexity. An attacker can exploit this to read limited files or potentially gain unauthorized access. Patches are available in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later.

Affected products

  • Synology DiskStation Manager 7.2.1 before 69057-10, 7.2.2 before 72806-7, 7.3.2 before 86009-2

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: patched: Patches released for DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later

References

Related threats