Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
History

Tue, 29 Jul 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology router Manager
CPEs cpe:2.3:o:synology:router_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:-:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update1:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update2:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update3:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update4:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update5:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update6:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update7:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update8:*:*:*:*:*:*
Vendors & Products Synology
Synology router Manager

Wed, 04 Dec 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Dec 2024 07:15:00 +0000

Type Values Removed Values Added
Description Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published: 2024-12-04T06:59:56.673Z

Updated: 2024-12-04T14:09:11.756Z

Reserved: 2024-11-19T03:51:29.578Z

Link: CVE-2024-11398

cve-icon Vulnrichment

Updated: 2024-12-04T14:05:25.399Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-04T07:15:05.983

Modified: 2025-07-29T19:42:50.477

Link: CVE-2024-11398

cve-icon Redhat

No data.