Executive brief
Synology DiskStation Manager (DSM) is a network-attached storage operating system used to manage file storage and backup for businesses and individuals. A flaw in its Upload API allows authenticated users to write arbitrary files to the system and cause service disruptions, potentially compromising data integrity and system availability.
Technical details
An external control of file name or path vulnerability (CWE-73) exists in the Upload API of Synology DiskStation Manager. The vulnerability allows remote authenticated users to manipulate file paths during upload operations, enabling them to write arbitrary files to unintended locations on the system. Attack requires valid authentication credentials and network access to the DSM web interface. An attacker can achieve arbitrary file write and denial-of-service impacts. Patches are available in DSM 7.2.1-69057-12 or later, 7.2.2-72806-9 or later, 7.3.2-86009-4 or later, and 7.4-90075 or later.
Affected products
- Synology DiskStation Manager (DSM) 7.2.1 before 69057-12, 7.2.2 before 72806-9, 7.3.2 before 86009-4, 7.4 before 90075
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Patches released simultaneously with disclosure