CVE-2018-13284: Synology Diskstation Manager

High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.

Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.

Affected products

  • Synology Diskstation Manager: from 5.2, before 5.2-5967-8 (fixed in 5.2-5967-8); from 6.0, before 6.0.3-8754-8 (fixed in 6.0.3-8754-8); from 6.1, before 6.1.7-15284-1 (fixed in 6.1.7-15284-1); from 6.2, before 6.2-23739-1 (fixed in 6.2-23739-1)

Published 2019-04-01. Last modified 2026-06-17.