← Vulnerability feed

Vulnerability record · CVE-2023-41738 · published 31 August 2023

CVE-2023-41738: Synology router manager vulnerability

Synology · Router Manager

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

8.8 CVSS 3.1 High EPSS 1.5% · top 26.1%
8.8CVSS 3.1 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-41738 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-27655Synology router manager improper privilege management vulnerabilityImproper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via i…EPSS 1.8%9.8CVE-2023-32956Synology router manager vulnerabilityImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager …EPSS 1.5%9.8CVE-2023-0077Synology router manager vulnerabilityInteger overflow or wraparound vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote att…EPSS 0.95%9.8CVE-2020-27654Synology router manager improper privilege management vulnerabilityImproper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands…EPSS 4.7%9.8CVE-2018-1160Netatalk dsi_opensess.c out-of-bounds write allows remote code executionNetatalk before 3.1.12 fails to bounds-check attacker-controlled data in dsi_opensess.c, producing an out-of-bounds write. A remote unauthenticated a…EPSS 87%analysed9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed9.0CVE-2020-27649Synology router manager improper certificate validation vulnerabilityImproper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers…EPSS 0.72%8.8CVE-2019-9501Synology router manager heap-based buffer overflow vulnerabilityThe Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 byte…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2023-41738), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.