CVE-2018-13289: Infoleak
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folderpath or (2) realpath parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this information exposure vulnerability?
The vulnerability ID for this information exposure vulnerability is CVE-2018-13289.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Synology Router Manager (SRM) before version 1.1.7-6941-2.
How does this vulnerability work?
This vulnerability allows remote attackers to obtain sensitive information by exploiting the folder_path or real_path parameter in SYNO.FolderSharing.List in Synology Router Manager (SRM).
What is the severity of CVE-2018-13289?
The severity of CVE-2018-13289 is medium with a CVSS score of 5.3.
How can I fix this information exposure vulnerability?
To fix this vulnerability, update Synology Router Manager (SRM) to version 1.1.7-6941-2 or later.