CVE-2018-14908: Samsung Syncthru Web Service

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action.

Affected products

  • Samsung Syncthru Web Service: version 4.05.61 only

Published 2018-08-03. Last modified 2026-06-17.