Command Injection in Synology Video Station from Synology
CVE-2015-6912

Currently unrated

Key Information:

Vendor
Synology
Vendor
CVE Published:
11 September 2015

Summary

The vulnerability in Synology Video Station allows remote attackers to exploit shell metacharacters within the subtitle_codepage parameter in subtitle.cgi, leading to arbitrary command execution on vulnerable installations prior to version 1.5-0763. This could allow an attacker to execute malicious commands remotely, potentially compromising the affected systems and exposing sensitive data.

References

EPSS Score

17% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.