NAS Under Siege: Critical 9.8 CVSS Bug in Synology Telnet Opens the Door to Total Hijack
ID: 025a0a34-d297-52a1-aa4f-b7761d04d6c5
STIX ID: report--025a0a34-d297-52a1-aa4f-b7761d04d6c5
Feed Name: securityonline.info
Threat Score
Synology issued an urgent security advisory for CVE-2026-32746: a critical (CVSS 9.8) buffer-overflow vulnerability in GNU inetutils' telnetd that enables unauthenticated remote code execution on affected DiskStation Manager (DSM) versions. Synology provides fixed DSM release versions and recommends immediate upgrades or disabling the Telnet service as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
