CVE-2025-13392: Critical severity Synology DiskStation Manager (DSM) vulnerability
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13392?
CVE-2025-13392 has a high severity rating of 8.1.
How do I fix CVE-2025-13392?
To fix CVE-2025-13392, upgrade to Synology DiskStation Manager versions 7.2.2-72806-5 or 7.3.1-86003-1 or later.
What systems are affected by CVE-2025-13392?
CVE-2025-13392 affects versions of Synology DiskStation Manager (DSM) prior to 7.2.2-72806-5 and 7.3.1-86003-1.
Can CVE-2025-13392 be exploited remotely?
Yes, CVE-2025-13392 can be exploited remotely, allowing attackers to bypass authentication.
What is the impact of CVE-2025-13392?
The impact of CVE-2025-13392 includes potential unauthorized access due to improper checks for exceptional conditions.