CVE-2018-13292: Infoleak
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13292?
CVE-2018-13292 is an information exposure vulnerability in Synology Router Manager (SRM) that allows remote authenticated users to obtain sensitive information.
How does CVE-2018-13292 affect Synology Router Manager?
CVE-2018-13292 allows remote authenticated users to access sensitive information through the world readable configuration file in Synology Router Manager (SRM).
What is the severity of CVE-2018-13292?
CVE-2018-13292 has a severity rating of medium with a CVSS score of 4.3.
How can I fix CVE-2018-13292 in Synology Router Manager?
To fix CVE-2018-13292 in Synology Router Manager, it is recommended to update to version 1.1.7-6941-2 or later, as specified in the security advisory provided by Synology.
Where can I find more information about CVE-2018-13292?
You can find more information about CVE-2018-13292 in the security advisory provided by Synology at the following URL: https://www.synology.com/security/advisory/Synology_SA_18_48