CVE-2017-12074: Synology DNS Server

Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.

Affected products

  • Synology DNS Server: up to and including 2.2.0-3032

Published 2017-08-24. Last modified 2026-06-17.