CVE-2017-12079: Synology Photo Station

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.

Affected products

  • Synology Photo Station: from 6.8, before 6.8.1-3458 (fixed in 6.8.1-3458); from 6.3, before 6.3-2970 (fixed in 6.3-2970)

Published 2017-12-04. Last modified 2026-06-17.