CVE-2018-13286: Synology Diskstation Manager
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
Affected products
- Synology Diskstation Manager: from 5.2, before 5.2-5967-8 (fixed in 5.2-5967-8); from 6.0, before 6.0.3-8754-8 (fixed in 6.0.3-8754-8); from 6.1, before 6.1.7-15284-1 (fixed in 6.1.7-15284-1); from 6.2, before 6.2-23739-1 (fixed in 6.2-23739-1)
Published 2019-04-01. Last modified 2026-06-17.