Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic
Synology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.
CVE search metadata
CVE search record: CVE-2026-13639. Severity: critical. CVSS: 9.8. KEV: no. Product: DiskStation Manager (< 7.2.1-69057-12, < 7.2.2-72806-9, < 7.3.2-86009-4, < 7.4-90075), DiskStation Manager (7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075), DiskStation Manager (< 7.2.1-69057-10), DiskStation Manager (< 7.2.2-72806-7), DiskStation Manager (< 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-10, < 7.2.2-72806-7, < 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-12), DiskStation Manager (< 7.2.1-69057-12). Brief: Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/
CVE search record: CVE-2026-13684. Severity: critical. CVSS: 9.8. KEV: no. Product: DiskStation Manager (< 7.2.1-69057-12, < 7.2.2-72806-9, < 7.3.2-86009-4, < 7.4-90075), DiskStation Manager (7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075), DiskStation Manager (< 7.2.1-69057-10), DiskStation Manager (< 7.2.2-72806-7), DiskStation Manager (< 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-10, < 7.2.2-72806-7, < 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-12), DiskStation Manager (< 7.2.1-69057-12). Brief: Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/
CVE search record: CVE-2026-13673. Severity: high. CVSS: 8.8. KEV: no. Product: DiskStation Manager (< 7.2.1-69057-12, < 7.2.2-72806-9, < 7.3.2-86009-4, < 7.4-90075), DiskStation Manager (7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075), DiskStation Manager (< 7.2.1-69057-10), DiskStation Manager (< 7.2.2-72806-7), DiskStation Manager (< 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-10, < 7.2.2-72806-7, < 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-12), DiskStation Manager (< 7.2.1-69057-12). Brief: Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/
CVE search record: CVE-2026-40530. Severity: high. CVSS: 8.0. KEV: no. Product: DiskStation Manager (< 7.2.1-69057-12, < 7.2.2-72806-9, < 7.3.2-86009-4, < 7.4-90075), DiskStation Manager (7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075), DiskStation Manager (< 7.2.1-69057-10), DiskStation Manager (< 7.2.2-72806-7), DiskStation Manager (< 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-10, < 7.2.2-72806-7, < 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-12), DiskStation Manager (< 7.2.1-69057-12). Brief: Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/
CVE search record: CVE-2026-40539. Severity: high. CVSS: 7.1. KEV: no. Product: DiskStation Manager (< 7.2.1-69057-12, < 7.2.2-72806-9, < 7.3.2-86009-4, < 7.4-90075), DiskStation Manager (7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075), DiskStation Manager (< 7.2.1-69057-10), DiskStation Manager (< 7.2.2-72806-7), DiskStation Manager (< 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-10, < 7.2.2-72806-7, < 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-12), DiskStation Manager (< 7.2.1-69057-12). Brief: Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/
CVE search record: CVE-2026-6205. Severity: high. CVSS: 8.1. KEV: no. Product: DiskStation Manager (< 7.2.1-69057-12, < 7.2.2-72806-9, < 7.3.2-86009-4, < 7.4-90075), DiskStation Manager (7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075), DiskStation Manager (< 7.2.1-69057-10), DiskStation Manager (< 7.2.2-72806-7), DiskStation Manager (< 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-10, < 7.2.2-72806-7, < 7.3.2-86009-2), DiskStation Manager (< 7.2.1-69057-12), DiskStation Manager (< 7.2.1-69057-12). Brief: Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/
What's new
- 1. new product Sep 18, 13:12 via bsi
- 2. added CVE-2026-13673 +4 Sep 18, 13:12 via bsi
- 3. added coverage for DiskStation Manager (< 7.2.1-69057-12, < 7.2.2-72806-9, < 7.3.2-86009-4, < 7.4-90075) Sep 18, 10:06 via nvd
- 4. added coverage for DiskStation Manager (< 7.2.1-69057-10, < 7.2.2-72806-7, < 7.3.2-86009-2) Sep 18, 10:06 via nvd
- 5. added coverage for DiskStation Manager (< 7.2.1-69057-10) +2 products Sep 18, 10:05 via nvd
Synology DiskStation Manager (DSM) is affected by a critical vulnerability categorized as insufficient entropy within the system's authentication and login logic. This flaw, tracked as CVE-2026-13639, enables remote, unauthenticated attackers to manipulate session generation or authentication tokens due to predictable or weak entropy sources. Exploitation of this vulnerability grants unauthorized actors the ability to read or write arbitrary files on the underlying filesystem, potentially leading to full system compromise. Additionally, attackers can leverage this flaw to induce a denial-of-service (DoS) condition, rendering the NAS device unresponsive. The vulnerability affects multiple versions of DSM, including those prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Organizations utilizing Synology NAS devices are urged to apply the vendor-provided patches immediately to mitigate the risk of remote file system exploitation.
Impact
Successful exploitation of CVE-2026-13639 results in a complete loss of confidentiality and integrity, as attackers can access or modify sensitive data stored on the NAS, including configuration files, databases, and user documents. The capacity for remote arbitrary file write allows for persistence mechanisms or code execution if an attacker can overwrite system binaries or startup scripts. The denial-of-service vector impacts business continuity by taking critical storage infrastructure offline.
Recommendation
Prioritized actions for security and IT operations teams:
- Upgrade all instances of Synology DiskStation Manager (DSM) to the following patched versions immediately: 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075.
- Restrict access to the DSM management interface to trusted internal networks or via a VPN, ensuring it is not exposed directly to the internet to prevent unauthenticated remote exploitation.
- Review system logs for unauthorized configuration changes or abnormal file access patterns following the application of security updates.
Immediate actions
Upgrade Synology DiskStation Manager to version 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075.
Mitigations
Remove DSM management interface access from the public internet.
CVE-2026-13639