← Back to Threat Radar·Vendor focus

Synology Vulnerabilities Affecting Small Businesses

Synology NAS vulnerabilities exploited by ransomware groups targeting SMB file storage and backups.

11
Total CVEs
0
Critical
0
High risk
0
CISA KEV
Last updated: April 21, 2026 · Data: NVD · CISA KEV · EPSS
CVE-2024-10442medium

Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors.

29
SMB SCORE
CVSS 10.0
EPSS 0.9%
CVE-2024-50630medium

Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.

27
SMB SCORE
CVSS 7.5
EPSS 0.7%
CVE-2024-11131medium

A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.

27
SMB SCORE
CVSS 9.8
EPSS 0.6%
CVE-2024-10441medium

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.

27
SMB SCORE
CVSS 9.8
EPSS 0.6%
CVE-2024-50631medium

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing daemon in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to inject SQL commands, limited to write operations, via unspecified vectors.

26
SMB SCORE
CVSS 7.5
EPSS 0.5%
CVE-2024-53286medium

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to execute arbitrary code via unspecified vectors.

24
SMB SCORE
CVSS 7.2
EPSS 0.4%
CVE-2024-50629medium

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.

21
SMB SCORE
CVSS 5.3
EPSS 0.1%
CVE-2024-53287low

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.

18
SMB SCORE
CVSS 5.9
EPSS 0.1%
CVE-2024-53288low

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors.

18
SMB SCORE
CVSS 5.9
EPSS 0.1%
CVE-2024-10444low

Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.

16
SMB SCORE
CVSS 7.5
EPSS 0.1%
CVE-2024-10445low

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.

9
SMB SCORE
CVSS 4.3
EPSS 0.1%
Related — other vendors affecting SMB
Microsoft vulnerabilities →Fortinet vulnerabilities →Cisco vulnerabilities →SonicWall vulnerabilities →Apache vulnerabilities →WordPress vulnerabilities →Veeam vulnerabilities →QNAP vulnerabilities →