📦 Router Manager

by Synology

🔍 What is Router Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-32956

CRITICAL CVSS 9.8 May 16, 2023

This CVE describes an OS command injection vulnerability in Synology Router Manager's CGI component that allows remote attackers to execute arbitrary commands on affected routers. Attackers can potent...

CVE-2020-27654

CRITICAL CVSS 9.8 Oct 29, 2020

CVE-2020-27654 is an improper access control vulnerability in the lbd service of Synology Router Manager (SRM) that allows remote attackers to execute arbitrary commands without authentication. Attack...

CVE-2018-1160

CRITICAL CVSS 9.8 Dec 20, 2018

CVE-2018-1160 is a critical vulnerability in Netatalk that allows remote unauthenticated attackers to execute arbitrary code due to an out-of-bounds write in dsi_opensess.c. It affects systems running...

CVE-2025-29846

HIGH CVSS 7.2 Dec 4, 2025

This vulnerability in Synology's portenable CGI allows authenticated remote users to query the status of installed packages. This information disclosure could help attackers map the system for further...

CVE-2024-53286

HIGH CVSS 7.2 Jul 23, 2025

This CVE describes an OS command injection vulnerability in Synology Router Manager's DDNS functionality. Authenticated administrators can execute arbitrary commands on the router, potentially comprom...

CVE-2024-11398

HIGH CVSS 8.1 Dec 4, 2024

This path traversal vulnerability in Synology Router Manager allows authenticated remote attackers to delete arbitrary files on affected systems by exploiting improper path validation in the OTP reset...

CVE-2024-39348

HIGH CVSS 7.5 Jun 28, 2024

This vulnerability allows man-in-the-middle attackers to execute arbitrary code on Synology routers by exploiting AirPrint functionality that downloads code without proper integrity checks. It affects...

CVE-2023-32955

HIGH CVSS 8.1 May 16, 2023

This CVE describes an OS command injection vulnerability in Synology Router Manager's DHCP client functionality. Attackers with man-in-the-middle position can execute arbitrary commands on affected ro...

CVE-2025-29843

MEDIUM CVSS 5.4 Dec 4, 2025

This vulnerability in Synology FileStation's thumb.cgi component allows authenticated users to read and write image files they shouldn't have access to. It affects Synology NAS devices running DSM wit...

CVE-2025-29844

MEDIUM CVSS 4.3 Dec 4, 2025

This vulnerability allows remote authenticated users to read file metadata and path information through a FileStation CGI component. It affects Synology NAS devices running vulnerable versions of DSM....

CVE-2025-29845

MEDIUM CVSS 4.3 Dec 4, 2025

This vulnerability allows authenticated users to read .srt subtitle files on Synology Video Station systems. It affects Synology Video Station installations where users have authenticated access to th...

CVE-2024-53288

MEDIUM CVSS 5.9 Jul 23, 2025

This is a stored cross-site scripting (XSS) vulnerability in Synology Router Manager's NTP Region functionality. Authenticated administrators can inject malicious scripts that execute when other users...

CVE-2024-53284

MEDIUM CVSS 5.9 Dec 9, 2024

This is a stored cross-site scripting (XSS) vulnerability in Synology Router Manager's WiFi Connect Setting functionality. It allows authenticated administrators to inject malicious scripts that can r...

CVE-2024-53280

MEDIUM CVSS 5.9 Dec 9, 2024

This is a stored cross-site scripting (XSS) vulnerability in Synology Router Manager's network center policy route functionality. It allows authenticated administrators to inject malicious scripts tha...

CVE-2024-53282

MEDIUM CVSS 5.9 Dec 9, 2024

This is a stored cross-site scripting (XSS) vulnerability in Synology Router Manager's WiFi Connect MAC Filter functionality. It allows authenticated administrators to inject malicious scripts that ca...

CVE-2024-39347

MEDIUM CVSS 5.9 Jun 28, 2024

This vulnerability allows man-in-the-middle attackers to bypass firewall protections and access sensitive internal network resources on Synology routers. It affects Synology Router Manager (SRM) insta...