CVE-2018-13281: Synology Diskstation Manager
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.
Affected products
- Synology Diskstation Manager: from 6.1, before 6.1.7-15284-2 (fixed in 6.1.7-15284-2); from 6.2, before 6.2-23739-2 (fixed in 6.2-23739-2); version 5.2 only; version 6.0 only
- Synology Skynas: affected versions not specified
- Synology VS960HD: affected versions not specified
Published 2018-10-31. Last modified 2026-06-17.