CVE-2017-15889
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
- Affected products
- Synology Diskstation Manager
- Synology Diskstation Manager
- < 5.2-5967-5
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 73.7% (99th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2017-12-04
CVE-2017-15889 at NVD
5 known exploits for CVE-2017-15889
Proof-of-concept code and exploit modules indexed by Sploitus
Synology DiskStation Manager - smart.cgi Remote Command Execution Exploit
Synology DiskStation Manager smart.cgi - Remote Command Execution
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
Synology DiskStation Manager smart.cgi Remote Command Execution
Synology DiskStation Manager smart.cgi Remote Command Execution