CVE-2023-41738: OS Command Injection
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-41738?
CVE-2023-41738 is a vulnerability known as 'Improper neutralization of special elements used in an OS command (OS Command Injection)' in Synology Router Manager (SRM) before version 1.3.1-9346-6.
What is the severity of CVE-2023-41738?
CVE-2023-41738 has a severity score of 8.8 (high).
How does CVE-2023-41738 affect Synology Router Manager?
CVE-2023-41738 allows remote authenticated users to execute arbitrary commands in the Directory Domain Functionality of Synology Router Manager (SRM) before version 1.3.1-9346-6.
How can I fix CVE-2023-41738?
To fix CVE-2023-41738, update Synology Router Manager (SRM) to version 1.3.1-9346-6 or later.
Where can I find more information about CVE-2023-41738?
You can find more information about CVE-2023-41738 in the Synology security advisory at https://www.synology.com/en-global/security/advisory/Synology_SA_23_10.