CVE-2018-8914: Synology Media Server
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.
Affected products
- Synology Media Server: from 1.4, before 1.4-2654 (fixed in 1.4-2654); from 1.7, before 1.7.6-2842 (fixed in 1.7.6-2842)
Published 2018-05-10. Last modified 2026-06-17.