CVE-2015-6912: Synology Video Station

High severity, CVSS 10.0. EPSS: 11.8% chance of exploitation in the next 30 days.

Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.

Affected products

  • Synology Video Station: up to and including 1.5-0757

Published 2015-09-11. Last modified 2026-06-17.