Tuesday, September 10, 2013

Synology DSM <= 4.3-3776 multiple vulnerabilities

After a reverse engineering of the firmware, I found some interesting vulnerabilities that affects the latest version of the Synology DSM:

  • Remote file download 
  • Command injection
  • Partial remote content download
  • Cross-site scripting

No comments: