CVE-2024-39347: Synology Router Manager
Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.
Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.
Affected products
- Synology Router Manager: from 1.2, before 1.2.5-8227 (fixed in 1.2.5-8227); from 1.3, before 1.3.1-9346 (fixed in 1.3.1-9346); version 1.2.5-8227 only; version 1.3.1-9346 only
Published 2024-06-28. Last modified 2026-06-17.