CVE-2024-53284: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53284?
CVE-2024-53284 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2024-53284?
To mitigate CVE-2024-53284, upgrade Synology Router Manager to version 1.3.1-9346-10 or later.
Who is affected by CVE-2024-53284?
CVE-2024-53284 affects remote authenticated users with administrator privileges on Synology Router Manager versions prior to 1.3.1-9346-10.
What kind of attack can be performed using CVE-2024-53284?
CVE-2024-53284 allows an attacker to inject arbitrary web scripts or HTML, leading to Cross-site Scripting (XSS) attacks.
Is my Synology Router vulnerable to CVE-2024-53284?
If you are using Synology Router Manager versions before 1.3.1-9346-10, your device is vulnerable to CVE-2024-53284.