CVE-2024-53282: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53282?
CVE-2024-53282 is classified as a high-severity Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2024-53282?
To mitigate CVE-2024-53282, update your Synology Router Manager to version 1.3.1-9346-10 or later.
Who is affected by CVE-2024-53282?
CVE-2024-53282 affects remote authenticated users with administrator privileges on Synology Router Manager versions prior to 1.3.1-9346-10.
What can attackers do with CVE-2024-53282?
Attackers can exploit CVE-2024-53282 to inject arbitrary web scripts or HTML into the Synology Router Manager interface.
When was CVE-2024-53282 reported?
CVE-2024-53282 was reported in the context of security vulnerabilities discovered in Synology Router Manager before the release of version 1.3.1-9346-10.