Improper Control of Dynamically-Managed Code Resources in Synology DiskStation Manager
CVE-2024-5401
4.3MEDIUM
Key Information:
- Vendor
Synology
- Vendor
- CVE Published:
- 4 December 2025
What is CVE-2024-5401?
A security vulnerability exists in the WebAPI component of Synology DiskStation Manager, allowing remote authenticated users to gain elevated privileges without proper authorization. This issue affects multiple versions prior to the specified updates, enabling unauthorized access through unspecified methods. Users are advised to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
DiskStation Manager (DSM) 7.2.2
DiskStation Manager (DSM) 7.2.2 < 7.2.2-72806
DiskStation Manager (DSM) 7.2.1 < 7.2.1-69057-2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vo Van Thong of GE Security (VNG) (https://www.linkedin.com/in/thongvv3/)