CVE-2026-40538: Low severity Synology DiskStation Manager (DSM) vulnerability
An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Synology DiskStation Manager (DSM)to a version that resolves this vulnerability.Fixed in 7.2.1-69057-10 - Upgrade
Upgrade
Synology DiskStation Manager (DSM)to a version that resolves this vulnerability.Fixed in 7.2.2-72806-7 - Upgrade
Upgrade
Synology DiskStation Manager (DSM)to a version that resolves this vulnerability.Fixed in 7.3.2-86009-2
Event History
Frequently Asked Questions
Which DSM releases include the fix?
The issue is addressed in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2. DSM releases before those versions are affected.
Does an attacker need an account or user interaction to exploit this?
No privileges or user interaction are required according to the supplied vector. Exploitation is remote but has high attack complexity and relies on brute-force attempts.
What is the expected impact if exploitation succeeds?
A successful attacker can read limited files. The supplied impact information indicates limited confidentiality impact, with no integrity or availability impact.