Synology NAS DSM 5.2 远程代码执行漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

![](https://images.seebug.org/contribute/22b20247-38b7-4180-8415-0fdfafc968c3) ### Getting started I recently bought a Synology DS416 NAS and noticed during the set-up process you are first required to download the device firmware, which is then flashed to the device via the setup web interface. Interested in my new devices security, I decided to take a look at the firmware while the system was installing. Firstly, let’s download the DSM 5.2 firmware (unsure which versions are affected by this vulnerability) from the official Synology download center and identify what we are dealing with: ``` wget http://global.download.synology.com/download/DSM/release/5.2/5644/DSM_DS416_5644.pat file DSM_DS416_5644.pat DSM_DS416_5644.pat: POSIX tar archive (GNU) tar -xvf DSM_DS416_5644.pat ``` ![](https://images.seebug.org/contribute/0c92420c-057f-4a9c-97a7-7ac6b8aa3025) So, the archived DSM_DS416_5644.pat file contains a number of subsidiary files and packages, as well as what looks like a...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息