CVE-2018-8918: Synology Router Manager

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

Affected products

  • Synology Router Manager: before 1.1.7-6941 (fixed in 1.1.7-6941)

Published 2018-12-24. Last modified 2026-06-17.