CVE-2024-47272: Synology Surveillance Station

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file write via unspecified vectors.

Affected products

  • Synology Surveillance Station: before 9.2.2-11575 (fixed in 9.2.2-11575); before 9.2.2-9575 (fixed in 9.2.2-9575)

Published 2026-05-27. Last modified 2026-06-17.