Home

Description

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.

PUBLISHED Reserved 2026-04-10 | Published 2026-04-10 | Updated 2026-04-10 | Assigner synology




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Problem types

Files or Directories Accessible to External Parties

Product status

Default status
affected

* (semver) before 1.4.5-0684
affected

Credits

Laurent Sibilla (https://www.linkedin.com/in/lsibilla/) finder

References

www.synology.com/...obal/security/advisory/Synology_SA_26_05 (Synology-SA-26:05 Synology SSL VPN Client) vendor-advisory

cve.org (CVE-2021-47960)

nvd.nist.gov (CVE-2021-47960)

Download JSON