CVE-2016-10322: Synology Photo Station

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php.

Affected products

  • Synology Photo Station: up to and including 6.3-2954

Published 2017-04-10. Last modified 2026-06-17.