First published: Thu Aug 31 2023(Updated: )
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
Credit: security@synology.com security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | <1.3.1-9346-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41738 is a vulnerability known as 'Improper neutralization of special elements used in an OS command (OS Command Injection)' in Synology Router Manager (SRM) before version 1.3.1-9346-6.
CVE-2023-41738 has a severity score of 8.8 (high).
CVE-2023-41738 allows remote authenticated users to execute arbitrary commands in the Directory Domain Functionality of Synology Router Manager (SRM) before version 1.3.1-9346-6.
To fix CVE-2023-41738, update Synology Router Manager (SRM) to version 1.3.1-9346-6 or later.
You can find more information about CVE-2023-41738 in the Synology security advisory at https://www.synology.com/en-global/security/advisory/Synology_SA_23_10.