Back Gbhackers Synology DiskStation Manager Vulnerability Puts Users at Risk of Remote Command ...
Synology has issued an urgent security update for its DiskStation Manager (DSM) software to address a critical vulnerability.
If left unpatched, this flaw could allow unauthenticated remote attackers to execute arbitrary commands on affected network-attached storage (NAS) devices.
Tracked under security advisory Synology-SA-26:03 , this ongoing security event requires immediate attention from system administrators to protect sensitive stored data against unauthorized network intrusions.
The vulnerability is officially tracked as CVE-2026-32746 and carries a maximum Critical CVSS v3 base score of 9.8 out of 10.
The security weakness originates within the telnetd service of the GNU Inetutils package, specifically impacting software versions up to 2.7.
The core issue is a classic buffer overflow defect , categorized under CWE-120. This flaw is located in the LINEMODE SLC (Set Local Characters) suboption handler of the Telnet daemon.
Because the software’s add_slc function fails to check whether the memory buffer is full before writing new data, it creates an out-of-bounds write condition.
Because network-attached storage devices often hold essential business backups and sensitive personal files, a remote command execution flaw of this magnitude poses a severe risk.
Attackers leveraging this vulnerability could potentially deploy ransomware, steal sensitive data, or use the compromised NAS as a pivot point to attack other devices on the internal network.
The vulnerability currently impacts several recent versions of Synology’s core operating systems.
While security patches are actively available for the main DSM product line, fixes for some specialized systems are still in development.
Fortunately, related platforms like BeeStation OS 1.4, Synology Router Manager (SRM) 1.3, and VS600HD 1.2 are completely unaffected.
Affected Products and Fixes
To secure their infrastructure, network administrators must apply the latest firmware updates as soon as they become available.
For devices where the patch is still ongoing, Synology strongly recommends an immediate workaround. Administrators should disable the Telnet service entirely to eliminate the attack vector.
To apply this mitigation, users must log into their NAS, open the Control Panel, navigate to the Terminal settings, uncheck the Enable Telnet service box, and click Apply.
In modern network environments, legacy plain-text protocols like Telnet should generally remain disabled in favor of encrypted alternatives like SSH.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
A fast-evolving information‑stealing malware dubbed “Torg Grabber” that has shifted from simple Telegram‑based exfiltration to…
Fake screenshot links are being used to quietly deploy a multi‑stage backdoor against Web3 customer…
A critical security flaw has been identified in the IDrive Cloud Backup Client for Windows,…
A newly identified malware loader dubbed “Kiss Loader” is emerging as a potential threat, leveraging…
Yesterday’s password leak can become tomorrow’s identity crisis. According to research firm Gitnux, account-takeover attacks…
Fake npm install messages are the latest social engineering trick in the open source supply…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
