Threat Advisory

Two Critical Flaws Let Remote Attackers Read or Write Arbitrary Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in DiskStation Manager, posing significant risks to network-attached storage infrastructure. The flaws range from low to critical severity, with the most severe reaching a maximum CVSS score of 9.8. Unauthenticated remote attackers can leverage these critical flaws to compromise system integrity, access sensitive data, or render devices unavailable. Organizations deploying these storage systems face elevated exposure to unauthorized file operations and service disruption. Immediate remediation is required to safeguard stored assets and maintain system availability across affected enterprise environments.

CVE-2026-13684: This critical vulnerability stems from an output-encoding flaw within the SCGI component, assigned a CVSS score of 9.8. Unauthenticated remote attackers can exploit this weakness without requiring user interaction. Successful exploitation allows attackers to execute arbitrary read and write operations on system files or trigger a denial-of-service state. This flaw presents a severe risk to device operational integrity and data privacy.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in DiskStation Manager, posing significant risks to network-attached storage infrastructure. The flaws range from low to critical severity, with the most severe reaching a maximum CVSS score of 9.8. Unauthenticated remote attackers can leverage these critical flaws to compromise system integrity, access sensitive data, or render devices unavailable. Organizations deploying these storage systems face elevated exposure to unauthorized file operations and service disruption. Immediate remediation is required to safeguard stored assets and maintain system availability across affected enterprise environments.

CVE-2026-13684: This critical vulnerability stems from an output-encoding flaw within the SCGI component, assigned a CVSS score of 9.8. Unauthenticated remote attackers can exploit this weakness without requiring user interaction. Successful exploitation allows attackers to execute arbitrary read and write operations on system files or trigger a denial-of-service state. This flaw presents a severe risk to device operational integrity and data privacy.[emaillocker id="1283"]

CVE-2026-13639: Identified as an insufficient-entropy flaw within the system login logic, this critical vulnerability carries a CVSS score of 9.8. Remote attackers can exploit the issue without prior authentication or user intervention. The impact includes unauthorized file manipulation, arbitrary file reading, and potential denial-of-service conditions. Unauthenticated exposure makes this vulnerability a primary vector for storage compromise.

CVE-2026-13673: This high-severity flaw affects the LDAP API component, carrying a CVSS score of 8.8. An authenticated remote attacker can exploit this issue to execute unauthorized file write operations. While authentication is required, successful exploitation allows malicious actors to modify critical files. The vulnerability compromises data integrity across the core management interface.

CVE-2026-6205: Located within the Upload API component, this vulnerability is rated high severity with a CVSS score of 8.1. Authenticated users can leverage this flaw to perform unauthorized file write actions on the target device. Exploitation disrupts the integrity of stored content and underlying applications. Restricted access controls mitigate unauthenticated risk, but internal threat vectors remain.

CVE-2026-13635: This medium-severity issue carries a CVSS score of 5.3 and involves improper handling of input leading to potential injection vulnerabilities. Exploitation requires user authentication and specific API interactions. A successful attack can result in limited privilege escalation or unauthorized data modification. The overall operational impact is moderate compared to critical remote flaws.

CVE-2026-13623: Assigned a CVSS score of 4.8, this medium-severity flaw relates to improper input handling, including potential CRLF injection. Authenticated users can manipulate specific requests to alter application behavior or headers. Impact is primarily restricted to session manipulation and minor data leakage. The vulnerability presents limited risk to overall system availability.

CVE-2026-13666: This low-severity vulnerability possesses a CVSS score of 3.5 and involves cross-site scripting vulnerabilities in administrative interfaces. Exploitation necessitates administrative privileges and targeted user interaction. Successful execution allows script injection within the context of the user session. The attack surface remains limited due to high privilege requirements.

CVE-2026-13683: Rated low severity with a CVSS score of 2.7, this flaw involves SQL injection risks in restricted management features. An attacker must possess administrator-level access to execute arbitrary database queries. The scope of impact is highly localized due to pre-existing elevated access levels. It poses minimal threat to overall infrastructure security.

Prompt application of security updates is essential to prevent potential exploitation and maintain robust defense postures. System administrators must prioritize patching unauthenticated entry points to mitigate remote exploitation risks. Comprehensive security practices, combined with timely updates, ensure continuous protection against infrastructure compromise.

RECOMMENDATION:

We recommend you to update Synology DSM to version 7.4-90075.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu