Description
Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37910 | Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors. |
References
History
Thu, 07 Aug 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology router Manager |
|
| CPEs | cpe:2.3:o:synology:router_manager:*:*:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:-:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update10:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update1:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update2:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update3:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update4:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update5:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update6:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update7:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update8:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update9:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:-:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update1:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update2:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update3:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update4:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update5:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update6:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update7:*:*:*:*:*:* |
|
| Vendors & Products |
Synology
Synology router Manager |
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2024-08-02T04:26:14.241Z
Reserved: 2024-06-24T10:57:17.890Z
Link: CVE-2024-39347
Updated: 2024-08-02T04:26:14.241Z
Status : Analyzed
Published: 2024-06-28T07:15:05.743
Modified: 2025-08-07T13:46:42.330
Link: CVE-2024-39347
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD