CVE-2024-11398: Synology Router Manager

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.

Affected products

  • Synology Router Manager: from 1.3, before 1.3.1-9346 (fixed in 1.3.1-9346); version 1.3.1-9346 only

Published 2024-12-04. Last modified 2026-06-17.