logo

Synology SSL VPN Client Vulnerability Enabled Remote Access to Sensitive Files

ID: e74c47d0-2b2b-5394-a057-3c60314720fb

STIX ID: report--e74c47d0-2b2b-5394-a057-3c60314720fb

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Divya

...
...

Synology released an advisory (Synology-SA-26:05) addressing two vulnerabilities in its SSL VPN Client: CVE-2021-47960 (local file disclosure via a loopback-bound HTTP server, CVSS 6.5) and CVE-2021-47961 (plaintext storage of user passwords allowing compromise of PINs and VPN credentials, CVSS 8.1). Both flaws require user interaction via malicious webpages (social engineering) and can lead to unauthorized access to VPN configurations, certificates, and interception of VPN traffic; Synology fixed the issues in version 1.4.5-0684 and recommends immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.