← Back to browse · API

CVE-2024-29241

Severity
CRITICAL
CVSS
9.9
EPSS
0.00756
Risk score
39.86
CISA KEV
No
PoC
No
Published
2024-03-28
Modified
2025-08-12
First seen
2026-08-07
Aliases
EUVD-2024-26255, GHSA-27MX-R8CM-2RX5
Products
Synology:Surveillance Station, Synology:Surveillance Station * <9.2.0-11289, Synology:Surveillance Station * <9.2.0-9289
Sources
euvd EUVD-2024-26255

Description

Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors.

References