Synology Router Manager (SRM) Vulnerability Allows Arbitrary Code Execution
CVE-2024-39348
What is CVE-2024-39348?
A vulnerability has been identified within the AirPrint functionality of Synology Router Manager (SRM) that allows for code to be downloaded without proper integrity checks. This flaw exposes systems running versions before 1.2.5-8227-11 and 1.3.1-9346-8 to potential man-in-the-middle attacks, where an attacker could execute arbitrary code by exploiting unspecified vectors. Organizations utilizing affected versions are urged to apply updates and implement security best practices to safeguard their networks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Synology Router Manager (SRM) 1.3
Synology Router Manager (SRM) 1.3 < 1.3.1-9346-8
Synology Router Manager (SRM) 1.2 < 1.2.5-8227-11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved