Executive brief
Synology DiskStation Manager (DSM) is the operating system for Synology NAS devices, which are commonly used in businesses for data storage and backup. An insufficiently protected login mechanism allows attackers to conduct brute-force attacks without proper rate limiting, potentially enabling unauthorized access to stored data and system configuration. This vulnerability affects DSM versions 7.2.1, 7.2.2, and 7.3.2 before specific patch levels.
Technical details
This vulnerability (CWE-307) involves improper restriction of excessive authentication attempts in the Auto block mechanism of Synology DSM. The vulnerability allows remote attackers to conduct brute-force attacks against login credentials with insufficient account lockout or rate-limiting protection. The attack requires no authentication and can be performed over the network, though with moderate complexity. An attacker can exploit this to read limited files or potentially gain unauthorized access. Patches are available in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later.
Affected products
- Synology DiskStation Manager 7.2.1 before 69057-10, 7.2.2 before 72806-7, 7.3.2 before 86009-2
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched: Patches released for DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later