CVE-2020-27654: Critical severity synology router manager vulnerability
Published Oct 29, 2020
·Updated
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
Affected Software
1 affected component
Synology Router Manager<1.2.4-8081
Event History
Oct 29, 2020
CVE Published
via MITRE·08:55 AM
Data Sourced
via MITRE·08:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-27654?
CVE-2020-27654 is an improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081.
2
How can remote attackers exploit CVE-2020-27654?
Remote attackers can exploit CVE-2020-27654 by executing arbitrary commands via port 7786/tcp or 7787/tcp.
3
What is the severity of CVE-2020-27654?
CVE-2020-27654 has a severity rating of 9.8 (critical).
4
Which software versions are affected by CVE-2020-27654?
CVE-2020-27654 affects Synology Router Manager (SRM) versions before 1.2.4-8081.
5
How can I fix CVE-2020-27654?
To fix CVE-2020-27654, update Synology Router Manager (SRM) to version 1.2.4-8081 or later.