Synology Download Station 3.8.x before 3.8.5-3475 and 3.x...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 20, 2025
Description
Published by the National Vulnerability Database
Aug 14, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 20, 2025
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.
References