{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/diskstation-manager--7.3.2-86009-2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:synology:diskstation_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-13639"},{"cvss":9.8,"id":"CVE-2026-13684"},{"cvss":8.8,"id":"CVE-2026-13673"},{"cvss":8,"id":"CVE-2026-40530"},{"cvss":7.1,"id":"CVE-2026-40539"},{"cvss":8.1,"id":"CVE-2026-6205"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DiskStation Manager (\u003c 7.2.1-69057-12, \u003c 7.2.2-72806-9, \u003c 7.3.2-86009-4, \u003c 7.4-90075)","DiskStation Manager (7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075)","DiskStation Manager (\u003c 7.2.1-69057-10)","DiskStation Manager (\u003c 7.2.2-72806-7)","DiskStation Manager (\u003c 7.3.2-86009-2)","DiskStation Manager (\u003c 7.2.1-69057-10, \u003c 7.2.2-72806-7, \u003c 7.3.2-86009-2)","DiskStation Manager (\u003c 7.2.1-69057-12)","DiskStation Manager (\u003c 7.2.1-69057-12)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","critical","remote-code-execution","file-read-write","dsm","file-access","synology","cve","crlf-injection","mitm","path-traversal","nas"],"_cs_type":"advisory","_cs_vendors":["Synology"],"content_html":"\u003cp\u003eSynology DiskStation Manager (DSM) is affected by a critical vulnerability categorized as insufficient entropy within the system's authentication and login logic. This flaw, tracked as CVE-2026-13639, enables remote, unauthenticated attackers to manipulate session generation or authentication tokens due to predictable or weak entropy sources. Exploitation of this vulnerability grants unauthorized actors the ability to read or write arbitrary files on the underlying filesystem, potentially leading to full system compromise. Additionally, attackers can leverage this flaw to induce a denial-of-service (DoS) condition, rendering the NAS device unresponsive. The vulnerability affects multiple versions of DSM, including those prior to 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Organizations utilizing Synology NAS devices are urged to apply the vendor-provided patches immediately to mitigate the risk of remote file system exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13639 results in a complete loss of confidentiality and integrity, as attackers can access or modify sensitive data stored on the NAS, including configuration files, databases, and user documents. The capacity for remote arbitrary file write allows for persistence mechanisms or code execution if an attacker can overwrite system binaries or startup scripts. The denial-of-service vector impacts business continuity by taking critical storage infrastructure offline.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Synology DiskStation Manager (DSM) to the following patched versions immediately: 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075.\u003c/li\u003e\n\u003cli\u003eRestrict access to the DSM management interface to trusted internal networks or via a VPN, ensuring it is not exposed directly to the internet to prevent unauthenticated remote exploitation.\u003c/li\u003e\n\u003cli\u003eReview system logs for unauthorized configuration changes or abnormal file access patterns following the application of security updates.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T13:12:53Z","date_published":"2026-09-18T10:04:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/","summary":"Synology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.","title":"Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic","url":"https://feed.craftedsignal.io/briefs/2026-09-synology-dsm-entropy/"}],"language":"en","title":"CraftedSignal Threat Feed - DiskStation Manager (\u003c 7.3.2-86009-2)","version":"https://jsonfeed.org/version/1.1"}