PT-2026-95313 · Synology · Diskstation Manager

·

CVE-2026-13666

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Synology DiskStation Manager (DSM) versions prior to 7.2.1-69057-12 Synology DiskStation Manager (DSM) versions prior to 7.2.2-72806-9 Synology DiskStation Manager (DSM) versions prior to 7.3.2-86009-4 Synology DiskStation Manager (DSM) versions prior to 7.4-90075
Description An improper neutralization of CRLF sequences, known as CRLF Injection, exists in the Sharing API. This issue allows remote authenticated users to write limited files if a victim clicks a sharing URL. CRLF Injection occurs when an application fails to properly filter Carriage Return (CR) and Line Feed (LF) characters, allowing an attacker to inject new lines into the HTTP response header.
Recommendations Update to version 7.2.1-69057-12 or later. Update to version 7.2.2-72806-9 or later. Update to version 7.3.2-86009-4 or later. Update to version 7.4-90075 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13666

Affected Products

Diskstation Manager