CVE-2024-47267: Synology Surveillance Station

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

Affected products

  • Synology Surveillance Station: before 9.2.2-11575 (fixed in 9.2.2-11575); before 9.2.2-9575 (fixed in 9.2.2-9575)

Published 2026-05-27. Last modified 2026-06-17.