CVE-2021-29083: OS Command Injection
Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-29083.
What is the title of this vulnerability?
The title of this vulnerability is 'Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter.'
What is the severity level of CVE-2021-29083?
The severity level of CVE-2021-29083 is critical with a CVSS score of 7.2.
How does the vulnerability CVE-2021-29083 affect Synology DiskStation Manager (DSM)?
The vulnerability CVE-2021-29083 affects Synology DiskStation Manager (DSM) versions before 6.2.3-25426-3.
How can an attacker exploit CVE-2021-29083?
An attacker can exploit CVE-2021-29083 by sending a specially crafted request with a malicious 'realname' parameter, allowing them to execute arbitrary code on the affected system.