Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54809 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. |
Tue, 29 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:synology:router_manager:*:*:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:-:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update10:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update1:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update2:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update3:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update4:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update5:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update6:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update7:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update8:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update9:*:*:*:*:*:* |
Wed, 23 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology router Manager |
|
| Vendors & Products |
Synology
Synology router Manager |
Wed, 23 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Jul 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified vectors. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2025-07-23T15:14:21.462Z
Reserved: 2024-11-20T03:43:14.920Z
Link: CVE-2024-53287
Updated: 2025-07-23T14:24:36.714Z
Status : Analyzed
Published: 2025-07-23T05:15:29.870
Modified: 2025-07-29T19:33:38.310
Link: CVE-2024-53287
No data.
OpenCVE Enrichment
Updated: 2025-07-23T17:35:54Z
EUVD