Vulnerability Details CVE-2024-11398
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.9%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2024-11398
-
cpe:2.3:o:synology:router_manager:1.3
-
cpe:2.3:o:synology:router_manager:1.3-9193
-
cpe:2.3:o:synology:router_manager:1.3.1-9346