First published: Sun Mar 31 2019(Updated: )
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | >=1.1<1.1.7-6941-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this information exposure vulnerability is CVE-2018-13289.
The affected software for this vulnerability is Synology Router Manager (SRM) before version 1.1.7-6941-2.
This vulnerability allows remote attackers to obtain sensitive information by exploiting the folder_path or real_path parameter in SYNO.FolderSharing.List in Synology Router Manager (SRM).
The severity of CVE-2018-13289 is medium with a CVSS score of 5.3.
To fix this vulnerability, update Synology Router Manager (SRM) to version 1.1.7-6941-2 or later.