<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>DiskStation Manager (DSM) &lt; 7.2.2-72806-5 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/diskstation-manager-dsm--7.2.2-72806-5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 27 May 2026 09:17:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/diskstation-manager-dsm--7.2.2-72806-5/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-13392 - Synology DiskStation Manager (DSM) Authentication Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-05-cve-2025-13392-dsm-auth-bypass/</link><pubDate>Wed, 27 May 2026 09:17:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-cve-2025-13392-dsm-auth-bypass/</guid><description>Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 is vulnerable to improper checks for unusual or exceptional conditions in SSO, allowing remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).</description><content:encoded><![CDATA[<p>CVE-2025-13392 describes an authentication bypass vulnerability affecting the SSO component of Synology DiskStation Manager (DSM). The vulnerability exists in versions prior to 7.2.2-72806-5 and 7.3.1-86003-1, while version 7.2.1-69057 is not affected. A remote attacker with prior knowledge of the distinguished name (DN) can exploit this flaw to bypass authentication. This vulnerability enables unauthorized access to Synology DiskStation Manager devices. Successful exploitation allows attackers to gain administrative access to the device and the data it stores. Given the widespread use of Synology NAS devices for both personal and business data storage, this vulnerability poses a significant risk.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a vulnerable Synology DSM instance running a version prior to 7.2.2-72806-5 or 7.3.1-86003-1.</li>
<li>Attacker obtains the distinguished name (DN) of a valid user account. This could be achieved through reconnaissance or data breaches.</li>
<li>Attacker crafts a malicious authentication request to the SSO service, leveraging the improper checks for unusual or exceptional conditions.</li>
<li>The crafted request utilizes the known DN to bypass the authentication process.</li>
<li>The SSO service incorrectly validates the malicious authentication request.</li>
<li>The attacker gains unauthorized access to the DSM instance with the privileges associated with the user whose DN was used.</li>
<li>The attacker can now access and modify files, settings, and configurations within the DSM.</li>
<li>The attacker can install malware, exfiltrate sensitive data, or disrupt services.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2025-13392 allows remote attackers to bypass authentication on Synology DiskStation Manager (DSM) devices. This can lead to complete compromise of the device and the data stored on it, including sensitive personal and business information. The impact can range from data theft and ransomware attacks to disruption of critical services provided by the NAS. Given the high CVSS score of 8.1, this vulnerability is considered a critical threat.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Synology DiskStation Manager (DSM) to versions 7.2.2-72806-5 or 7.3.1-86003-1, or later to patch CVE-2025-13392.</li>
<li>Monitor network traffic for suspicious authentication attempts to the Synology DSM SSO service. Deploy the Sigma rules provided to detect anomalous SSO authentication patterns.</li>
<li>Implement strong password policies and multi-factor authentication to mitigate the impact of potential credential compromise, although this vulnerability bypasses authentication entirely with a known DN.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2025-13392</category><category>synology</category></item></channel></rss>