First published: Tue May 16 2023(Updated: )
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | >=1.2<1.2.5-8227-6 | |
Synology Router Manager | >=1.3<1.3.1-9346-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-32956.
The title of this vulnerability is Improper neutralization of special elements used in an OS command (OS Command Injection) vulnerability.
The severity of CVE-2023-32956 is critical.
The Synology Router Manager (SRM) versions before 1.2.5-8227-6 and 1.3.1-9346-3 are affected by CVE-2023-32956.
Remote attackers can exploit CVE-2023-32956 to execute arbitrary code via unspecified vectors.