CVE-2014-2264: Synology Diskstation Manager

High severity, CVSS 7.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session.

Affected products

  • Synology Diskstation Manager: version 4.3-3810 only

Published 2014-03-02. Last modified 2026-06-17.