First published: Wed Apr 09 2025(Updated: )
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Synology DiskStation DS1823xs+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-10444.
Affected Software | Affected Version | How to fix |
---|---|---|
Synology DiskStation DS1823xs+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-CAN-25487 has a CVSS rating of 7.5, indicating it is a high-severity vulnerability.
To fix ZDI-CAN-25487, ensure that you have applied the latest firmware updates provided by Synology for the DiskStation DS1823xs+.
ZDI-CAN-25487 affects installations of Synology DiskStation DS1823xs+ devices that have not been patched.
An attacker can bypass authentication on affected Synology DiskStation DS1823xs+ installations, allowing unauthorized access.
No, authentication is not required to exploit the ZDI-CAN-25487 vulnerability.