← Vulnerability feed

Vulnerability record · CVE-2017-9554 · published 24 July 2017

CVE-2017-9554: Synology DSM forget_passwd.cgi username enumeration

Synology · Diskstation Manager

Synology DiskStation Manager (DSM) before 6.1.3-15152 contains an information exposure flaw in forget_passwd.cgi that lets remote attackers enumerate valid usernames. Because the endpoint is reachable without authentication, it gives attackers a reliable way to build a list of real accounts before password attacks.

5.3 CVSS 3.0 Medium EPSS 77% · top 0.5% CWE-200 · Information exposure
5.3CVSS 3.0 base score, v2 5.0
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw only exposes username validity and requires no authentication, but it is a useful reconnaissance step that feeds credential attacks and has high EPSS with a public exploit.

What it is

Synology DiskStation Manager (DSM) before 6.1.3-15152 contains an information exposure flaw in forget_passwd.cgi that lets remote attackers enumerate valid usernames. Because the endpoint is reachable without authentication, it gives attackers a reliable way to build a list of real accounts before password attacks.

Impact

An attacker learns which usernames exist on the DSM instance, improving the efficiency of brute-force, credential-stuffing or phishing attempts. No passwords or session data are exposed by this flaw itself.

Attack surface

Reachable over the network through the forget_passwd.cgi endpoint; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the DSM web interface can attempt enumeration.

Exploitation

Not listed in CISA KEV, but EPSS is 0.76716 (99.52nd percentile) and a public Exploit-DB entry exists, indicating observed or likely active exploitation interest.

What to do

  • Upgrade DSM to 6.1.3-15152 or later per Synology advisory SA_17_29_DSM.
  • Restrict network access to the DSM web interface to trusted management networks or VPN.
  • Enable account lockout and rate limiting on authentication and password-reset endpoints.
  • Disable or block the forget_passwd.cgi endpoint if password reset is not needed.
  • Monitor for repeated requests to forget_passwd.cgi from single sources.

Detection

  • Alert on high-volume or sequential requests to forget_passwd.cgi from one source IP.
  • Correlate username enumeration attempts with subsequent failed login bursts against DSM.
  • Review DSM web access logs for password-reset requests from unexpected external addresses.
  • Track requests to forget_passwd.cgi that return differing responses for valid versus invalid usernames.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9554 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed10.0CVE-2013-6955Synology DSM imageSelector.cgi arbitrary file append and code executionSynology DiskStation Manager (DSM) versions 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 contain a flaw in webman/image…EPSS 85%analysed9.8CVE-2025-13392Synology diskstation manager vulnerabilityImproper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-…EPSS 0.53%9.8CVE-2024-10441Synology beestation os vulnerabilityImproper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskS…EPSS 1.2%9.8CVE-2022-27625Synology diskstation manager memory buffer overflow vulnerabilityA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of…EPSS 1.6%9.8CVE-2022-27624Synology diskstation manager memory buffer overflow vulnerabilityA vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of …EPSS 1.6%9.8CVE-2022-22687Synology diskstation manager classic buffer overflow vulnerabilityBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager …EPSS 2.4%9.8CVE-2021-43926Synology diskstation manager sql injection vulnerabilityImproper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskSt…EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2017-9554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.