logo

Synology NAS DSM Account Takeover: When Random is not Secure

ID: 81f26cd4-5e12-546b-bf53-a69eab5933ef

STIX ID: report--81f26cd4-5e12-546b-bf53-a69eab5933ef

Feed Name: Claroty Team82

Threat Score
30/100

Date Published: 2024-01-19

Date Updated: 2026-04-17

Author: Sharon Brizinov

...
...

Team82 discovered that Synology DSM's installation wizard used the insecure JavaScript Math.random() to generate the built-in admin password, enabling an attacker who can leak several Math.random()-derived GUIDs to reconstruct the XorShift128 PRNG seed and recover the admin password; the team produced a PoC, disclosed the issue as CVE-2023-2729, and Synology released a patch (DSM 7.2-64561+).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.