First published: Thu Apr 01 2021(Updated: )
Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation Manager | <6.2.3-25426-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-29083.
The title of this vulnerability is 'Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated users to execute arbitrary code via realname parameter.'
The severity level of CVE-2021-29083 is critical with a CVSS score of 7.2.
The vulnerability CVE-2021-29083 affects Synology DiskStation Manager (DSM) versions before 6.2.3-25426-3.
An attacker can exploit CVE-2021-29083 by sending a specially crafted request with a malicious 'realname' parameter, allowing them to execute arbitrary code on the affected system.