logo

NAS Under Siege: Critical 9.8 CVSS Bug in Synology Telnet Opens the Door to Total Hijack

ID: 025a0a34-d297-52a1-aa4f-b7761d04d6c5

STIX ID: report--025a0a34-d297-52a1-aa4f-b7761d04d6c5

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

Synology issued an urgent security advisory for CVE-2026-32746: a critical (CVSS 9.8) buffer-overflow vulnerability in GNU inetutils' telnetd that enables unauthenticated remote code execution on affected DiskStation Manager (DSM) versions. Synology provides fixed DSM release versions and recommends immediate upgrades or disabling the Telnet service as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.