CVE-2024-13987: Synology Radius Server

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or write limited files in SRM and conduct limited denial-of-service via unspecified vectors.

Affected products

  • Synology Radius Server: before 3.0.27-0453 (fixed in 3.0.27-0453); before 3.0.27-0516 (fixed in 3.0.27-0516); before 3.0.27-0139 (fixed in 3.0.27-0139)

Published 2025-08-29. Last modified 2026-09-26.