Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37910 | Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to access highly sensitive intranet resources via unspecified vectors. |
Thu, 07 Aug 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology router Manager |
|
| CPEs | cpe:2.3:o:synology:router_manager:*:*:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:-:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update10:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update1:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update2:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update3:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update4:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update5:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update6:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update7:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update8:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.2.5-8227:update9:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:-:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update1:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update2:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update3:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update4:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update5:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update6:*:*:*:*:*:* cpe:2.3:o:synology:router_manager:1.3.1-9346:update7:*:*:*:*:*:* |
|
| Vendors & Products |
Synology
Synology router Manager |
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2024-08-02T04:26:14.241Z
Reserved: 2024-06-24T10:57:17.890Z
Link: CVE-2024-39347
Updated: 2024-08-02T04:26:14.241Z
Status : Analyzed
Published: 2024-06-28T07:15:05.743
Modified: 2026-06-17T07:41:46.037
Link: CVE-2024-39347
No data.
OpenCVE Enrichment
No data.
-
CWE-276
Incorrect Default Permissions
EUVD