CVE-2017-16772: Synology Photo Station
High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
Affected products
- Synology Photo Station: from 6.8, before 6.8.3-3463 (fixed in 6.8.3-3463); from 6.3, before 6.3-2971 (fixed in 6.3-2971)
Published 2018-03-22. Last modified 2026-06-17.