Command Injection in Synology Video Station from Synology
CVE-2015-6912
Currently unrated
Summary
The vulnerability in Synology Video Station allows remote attackers to exploit shell metacharacters within the subtitle_codepage parameter in subtitle.cgi, leading to arbitrary command execution on vulnerable installations prior to version 1.5-0763. This could allow an attacker to execute malicious commands remotely, potentially compromising the affected systems and exposing sensitive data.
References
EPSS Score
17% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved