← Vulnerability feed

Vulnerability record · CVE-2013-6955 · published 9 January 2014

CVE-2013-6955: Synology DSM imageSelector.cgi arbitrary file append and code execution

Synology · Diskstation Manager

Synology DiskStation Manager (DSM) versions 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 contain a flaw in webman/imageSelector.cgi. A pathname supplied in the SLICEUPLOAD X-TMP-FILE HTTP header is not properly validated, letting a remote attacker append data to arbitrary files. Because appended content can land in executable or configuration files, this can lead to arbitrary code execution on the NAS.

10.0 CVSS 2.0 High EPSS 85% · top 0.3% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10 and a very high EPSS probability makes this an urgent patching priority despite no KEV listing.

What it is

Synology DiskStation Manager (DSM) versions 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 contain a flaw in webman/imageSelector.cgi. A pathname supplied in the SLICEUPLOAD X-TMP-FILE HTTP header is not properly validated, letting a remote attacker append data to arbitrary files. Because appended content can land in executable or configuration files, this can lead to arbitrary code execution on the NAS.

Impact

An unauthenticated remote attacker can write attacker-controlled data into arbitrary files on the device, which can be leveraged to execute arbitrary code with the privileges of the web service. This gives full compromise of confidentiality, integrity, and availability of the affected DiskStation.

Attack surface

The flaw is reached over the network through the webman/imageSelector.cgi endpoint by manipulating the SLICEUPLOAD X-TMP-FILE HTTP header. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

The record is not listed in CISA KEV and has no exploit-tagged references, but EPSS is very high (0.84571, 99.7th percentile), indicating strong likelihood of exploitation activity.

What to do

  • Upgrade DSM to 4.0-2259, 4.2-3243, or 4.3-3810 Update 1 or later as applicable to the installed branch.
  • If immediate upgrade is not possible, restrict network access to the DSM web interface and imageSelector.cgi to trusted management networks only.
  • Disable or block the SLICEUPLOAD functionality and the imageSelector.cgi endpoint at the reverse proxy or web server layer if it is not required.
  • Monitor and audit file integrity on DSM volumes for unexpected modifications to scripts, configuration, or web-accessible files.
  • Apply vendor guidance from the CERT/CC vulnerability note (VU#615910) for additional workarounds.

Detection

  • Inspect HTTP request logs for POSTs to webman/imageSelector.cgi containing a SLICEUPLOAD X-TMP-FILE header with path traversal or absolute path values.
  • Alert on unexpected writes or modifications to executable, script, or configuration files on DSM shares and system paths.
  • Monitor for new or modified files in web-accessible directories that could be invoked as CGI or scripts.
  • Correlate outbound connections or process execution from the DSM web service following imageSelector.cgi requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.kb.cert.org/vuls/id/615910 US Government Resource
http://www.kb.cert.org/vuls/id/615910 US Government Resource

Track CVE-2013-6955 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed9.8CVE-2025-13392Synology diskstation manager vulnerabilityImproper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-…EPSS 0.53%9.8CVE-2024-10441Synology beestation os vulnerabilityImproper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskS…EPSS 1.2%9.8CVE-2022-27625Synology diskstation manager memory buffer overflow vulnerabilityA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of…EPSS 1.6%9.8CVE-2022-27624Synology diskstation manager memory buffer overflow vulnerabilityA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of …EPSS 1.6%9.8CVE-2022-22687Synology diskstation manager classic buffer overflow vulnerabilityBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager …EPSS 2.4%9.8CVE-2021-43926Synology diskstation manager sql injection vulnerabilityImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskSt…EPSS 0.88%9.8CVE-2021-43927Synology diskstation manager sql injection vulnerabilityImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology D…EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2013-6955), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.