CVE-2016-10331: Synology Photo Station
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.
Affected products
- Synology Photo Station: up to and including 6.5.2-3225
Published 2017-05-12. Last modified 2026-06-17.