CVE-2016-6554: Synology NAS servers DS107, DS116, and DS213, use default credentials
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6554?
CVE-2016-6554 poses a high security risk due to the use of non-random default credentials that can allow unauthorized access.
How do I fix CVE-2016-6554?
To resolve CVE-2016-6554, update the firmware of affected Synology NAS devices to the latest version that addresses this vulnerability.
Which Synology devices are affected by CVE-2016-6554?
CVE-2016-6554 affects the Synology NAS servers DS107 with firmware version 3.1-1639 and prior, and DS116, DS213 with firmware versions prior to 5.2-5644-1.
What kind of access can be gained through CVE-2016-6554?
A remote attacker can gain privileged access to a vulnerable Synology NAS device through CVE-2016-6554.
What are the default credentials vulnerable in CVE-2016-6554?
The default credentials exposed in CVE-2016-6554 are guest with a blank password and admin with a blank password.