CVE-2024-11398: Path Traversal
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11398?
CVE-2024-11398 is rated as a critical vulnerability due to its potential to allow remote authenticated users to delete arbitrary files.
How do I fix CVE-2024-11398?
To fix CVE-2024-11398, upgrade Synology Router Manager to version 1.3.1-9346-9 or later.
What is affected by CVE-2024-11398?
CVE-2024-11398 affects Synology Router Manager versions prior to 1.3.1-9346-9.
Who can exploit CVE-2024-11398?
CVE-2024-11398 can be exploited by remote authenticated users who have access to the OTP reset functionality.
What type of vulnerability is CVE-2024-11398?
CVE-2024-11398 is a Path Traversal vulnerability that allows unauthorized file deletion.