Authentication Bypass Vulnerability in Synology DiskStation Manager
CVE-2025-13392
8.1HIGH
What is CVE-2025-13392?
This vulnerability in Synology DiskStation Manager allows remote attackers to bypass authentication mechanisms by exploiting improper checks in the Single Sign-On (SSO) functionality. Attackers with prior knowledge of the distinguished name (DN) can leverage this flaw to gain unauthorized access, affecting users of specific versions prior to the patches implemented in 7.2.2-72806-5 and 7.3.1-86003-1. Being aware of this security risk is critical for maintaining the integrity of affected systems.
Affected Version(s)
DiskStation Manager (DSM) 7.3
DiskStation Manager (DSM) 7.3 < 7.3.1-86003-1
DiskStation Manager (DSM) 7.2.2 < 7.2.2-72806-5
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Le Trong Phuc (chanze@VRC) and Cao Ngoc Quy (Chino Kafuu)