← Vulnerability feed

Vulnerability record · CVE-2017-11155 · published 8 August 2017

CVE-2017-11155: Synology Photo Station index.php information exposure

Synology · Photo Station

Synology Photo Station before 6.7.3-3432 and 6.3-2967 exposes sensitive system information through index.php. The flaw is remotely reachable without authentication and leaks data that can aid further attacks against the appliance.

7.5 CVSS 3.0 High EPSS 47% · top 1.2% CWE-205 · CWE-205CWE-200 · Information exposure
7.5CVSS 3.0 base score, v2 5.0
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated remote information disclosure with a high CVSS score, public exploit code, and very high EPSS probability, though not known to be actively exploited in KEV.

What it is

Synology Photo Station before 6.7.3-3432 and 6.3-2967 exposes sensitive system information through index.php. The flaw is remotely reachable without authentication and leaks data that can aid further attacks against the appliance.

Impact

An unauthenticated attacker can read sensitive system information from the Photo Station web interface. That information can be used to fingerprint the device and plan follow-on exploitation.

Attack surface

Reached over the network via HTTP requests to index.php on the Photo Station web service. The CVSS vector shows no privileges and no user interaction required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.47432 (98.8th percentile) and an Exploit-DB entry exists, indicating public exploit code is available.

What to do

  • Upgrade Photo Station to 6.7.3-3432 or later (or 6.3-2967 or later on the 6.3 branch) per Synology SA_17_34_PhotoStation.
  • If patching is delayed, restrict network access to Photo Station to trusted networks or place it behind a VPN.
  • Disable or remove Photo Station if it is not required on the NAS.
  • Review NAS logs for unusual requests to index.php and rotate any credentials or tokens that may have been exposed.

Detection

  • Monitor web logs for anomalous or repeated requests to Photo Station index.php from untrusted sources.
  • Alert on access to Photo Station from external IP addresses or unexpected geographies.
  • Correlate Photo Station access with subsequent authentication attempts or exploitation activity on the NAS.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-29089Synology photo station sql injection vulnerabilityImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station b…EPSS 1.9%9.8CVE-2019-11821Synology photo station sql injection vulnerabilitySQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to ex…EPSS 1.7%9.8CVE-2017-11161Synology photo station sql injection vulnerabilityMultiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL comma…EPSS 1.2%9.8CVE-2017-11151Synology photo station improper authentication vulnerabilityA vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files wi…EPSS 16%9.8CVE-2017-11153Synology photo station deserialization of untrusted data vulnerabilityDeserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain a…EPSS 12%9.8CVE-2016-10329Synology photo station command injection vulnerabilityCommand injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell …EPSS 41%8.8CVE-2021-29092Synology photo station unrestricted file upload vulnerabilityUnrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote…EPSS 1.7%8.8CVE-2018-8925Synology photo station cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote attac…EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2017-11155), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.