Authentication Bypass Vulnerability in Synology DiskStation Manager
CVE-2025-13392

8.1HIGH

Key Information:

Vendor

Synology

Vendor
CVE Published:
27 May 2026

What is CVE-2025-13392?

This vulnerability in Synology DiskStation Manager allows remote attackers to bypass authentication mechanisms by exploiting improper checks in the Single Sign-On (SSO) functionality. Attackers with prior knowledge of the distinguished name (DN) can leverage this flaw to gain unauthorized access, affecting users of specific versions prior to the patches implemented in 7.2.2-72806-5 and 7.3.1-86003-1. Being aware of this security risk is critical for maintaining the integrity of affected systems.

Affected Version(s)

DiskStation Manager (DSM) 7.3

DiskStation Manager (DSM) 7.3 < 7.3.1-86003-1

DiskStation Manager (DSM) 7.2.2 < 7.2.2-72806-5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Trong Phuc (chanze@VRC) and Cao Ngoc Quy (Chino Kafuu)
.