Summary
Synology DiskStation Manager is prone to multiple vulnerabilities.
Impact
Please see the references for details about the impact.
Solution
Vendor updates are available.
Insight
Synology DSM versions 4.3-3776 and below suffer from remote file download, content disclosure, cross site scripting, and command injection vulnerabilities.
Affected
Synology DSM versions 4.3-3776 and below.
Detection
Tries to read /etc/synoinfo.conf by sending a special crafted HTTP GET request.
References