CVE-2023-0077: Synology Router Manager

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Integer overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to overflow buffers via unspecified vectors.

Affected products

  • Synology Router Manager: from 1.2, before 1.2.5-8227-6 (fixed in 1.2.5-8227-6); from 1.3, before 1.3.1-9346-3 (fixed in 1.3.1-9346-3)

Published 2023-01-05. Last modified 2026-06-17.