CVE-2024-53285: XSS
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53285?
CVE-2024-53285 has been classified with a medium severity level due to its potential for Cross-site Scripting attacks.
How do I fix CVE-2024-53285?
To fix CVE-2024-53285, update your Synology Router Manager to version 1.3.1-9346-10 or later.
Who is affected by CVE-2024-53285?
CVE-2024-53285 affects remote authenticated users with administrator privileges on affected versions of Synology Router Manager.
What kind of attack does CVE-2024-53285 enable?
CVE-2024-53285 enables attackers to inject arbitrary web scripts or HTML into the DDNS Record functionality.
Is there a workaround for CVE-2024-53285?
There are no official workarounds for CVE-2024-53285 other than applying the security update.