CVE-2024-53285: Synology Router Manager

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.

Affected products

  • Synology Router Manager: from 1.3, before 1.3.1-9346 (fixed in 1.3.1-9346); version 1.3.1-9346 only

Published 2024-12-09. Last modified 2026-06-17.