CVE-2016-10329: Synology Photo Station

Critical severity, CVSS 9.8. EPSS: 40.8% chance of exploitation in the next 30 days.

Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.

Affected products

  • Synology Photo Station: up to and including 6.5.2-3225

Published 2017-05-12. Last modified 2026-06-17.