CVE-2017-15889: Synology Diskstation Manager

High severity, CVSS 8.8. EPSS: 73.7% chance of exploitation in the next 30 days.

Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.

Affected products

  • Synology Diskstation Manager: before 5.2-5967-5 (fixed in 5.2-5967-5)

Published 2017-12-04. Last modified 2026-06-17.