Synology SRM
cpe:2.3:o:synology:router_manager:*:*:*:*:*:*:*
- 1.3
A path traversal vulnerability has been identified in the VideoPlayer2 subtitle CGI component of Synology routers running SRM 1.3. This vulnerability allows remote authenticated users to read .srt subtitle files, potentially leading to unauthorized access to sensitive information. The issue arises from improper validation of file paths, enabling users to manipulate file requests and access restricted files.
Exploitation of this vulnerability could result in unauthorized access to .srt files, which may contain sensitive information.
Users are advised to upgrade to Synology SRM version 1.3.1-9346-13 or above.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.