CVE-2018-14904: Samsung Syncthru Web Service

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid.

Affected products

  • Samsung Syncthru Web Service: version 4.05.61 only

Published 2018-08-03. Last modified 2026-06-17.