← Vulnerability feed

Vulnerability record · CVE-2013-6987 · published 31 December 2013

CVE-2013-6987: Synology diskstation manager path traversal vulnerability

Synology · Diskstation Manager

Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in webapi/FileStation/; (3) dlink parameter to fbdownload/; or unspecified parameters to (4) html5_upload.cgi, (5) file_download.cgi, (6) file_sharing.cgi, (7) file_MVCP.cgi, or (8) file_rename.cgi in webapi/FileStation/.

7.5 CVSS 2.0 High EPSS 15% · top 3.4% CWE-22 · Path traversal
7.5CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in webapi/FileStation/; (3) dlink parameter to fbdownload/; or unspecified parameters to (4) html5_upload.cgi, (5) file_download.cgi, (6) file_sharing.cgi, (7) file_MVCP.cgi, or (8) file_rename.cgi in webapi/FileStation/.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-6987 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed10.0CVE-2013-6955Synology DSM imageSelector.cgi arbitrary file append and code executionSynology DiskStation Manager (DSM) versions 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 contain a flaw in webman/image…EPSS 85%analysed9.8CVE-2025-13392Synology diskstation manager vulnerabilityImproper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-…EPSS 0.53%9.8CVE-2024-10441Synology beestation os vulnerabilityImproper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskS…EPSS 1.2%9.8CVE-2022-27625Synology diskstation manager memory buffer overflow vulnerabilityA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of…EPSS 1.6%9.8CVE-2022-27624Synology diskstation manager memory buffer overflow vulnerabilityA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of …EPSS 1.6%9.8CVE-2022-22687Synology diskstation manager classic buffer overflow vulnerabilityBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager …EPSS 2.4%9.8CVE-2021-43926Synology diskstation manager sql injection vulnerabilityImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskSt…EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2013-6987), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.