Synology-SA-17:71 SRM

Publish Time: 2017-11-15 13:27:01 UTC+8

Last Updated: 2017-12-08 16:12:50 UTC+8

Severity
Important
Status
Resolved

Abstract

CVE-2017-15895 allows remote authenticated users to write arbitrary files via a vulnerable version of Synology Router Manager (SRM).

Severity

Affected

  • Products
    • SRM 1.1
  • Models
    • All Synology models

Description

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.

Mitigation

None

Update Availability

To fix the security issue, please update SRM 1.1 to 1.1.5-6542-4 or above.