CVE-2026-13639

9.8

Synology · DiskStation Manager (DSM)

An insufficient entropy flaw in Synology DiskStation Manager login logic allows unauthenticated remote attackers to perform arbitrary file read/write operations and cause denial of service.

Executive summary

A critical vulnerability in Synology DiskStation Manager allows unauthenticated remote attackers to bypass security controls and gain unauthorized file access or disrupt system availability.

Vulnerability

The software suffers from insufficient entropy (CWE-331) within its login logic, which permits an unauthenticated attacker to manipulate authentication processes and achieve unauthorized file system access.

Business impact

The ability for an unauthenticated attacker to read or write arbitrary files on a network-attached storage device presents a severe risk to data confidentiality, integrity, and availability. With a CVSS score of 9.8, this vulnerability is classified as critical, as it provides a pathway for full system compromise, sensitive data exfiltration, or the deployment of malicious payloads that could lead to total loss of business operations.

Remediation

Immediate Action: Update all affected Synology DSM instances to versions 7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9, or 7.2.1-69057-12 immediately.

Proactive Monitoring: Review system access logs for anomalous login attempts or unexpected file modification events originating from unknown IP addresses.

Compensating Controls: Implement strict network segmentation and restrict management interface access to trusted internal IP ranges via a firewall to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the potential for full system compromise, administrators must prioritize patching this vulnerability across all exposed Synology devices. Ensure that firmware updates are applied immediately and verify that the management interface is not exposed to the public internet.

More Synology CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Lam Jun Rong (https://jro.sg), per the CVE Program record.