CVE-2024-11398
04.12.2024, 07:15
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Vendor | Product | Version |
---|---|---|
synology | router_manager | 1.3 ≤ 𝑥 < 1.3.1-9346 |
synology | router_manager | 1.3.1-9346 |
synology | router_manager | 1.3.1-9346:update1 |
synology | router_manager | 1.3.1-9346:update2 |
synology | router_manager | 1.3.1-9346:update3 |
synology | router_manager | 1.3.1-9346:update4 |
synology | router_manager | 1.3.1-9346:update5 |
synology | router_manager | 1.3.1-9346:update6 |
synology | router_manager | 1.3.1-9346:update7 |
synology | router_manager | 1.3.1-9346:update8 |
𝑥
= Vulnerable software versions