CVE-2025-13392
Received Received - Intake
Authentication Bypass in Synology DSM SSO

Publication date: 2026-05-27

Last updated on: 2026-05-27

Assigner: Synology Inc.

Description
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-05-27
Generated
2026-05-27
AI Q&A
2026-05-27
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
synology diskstation_manager to 7.3.1-86003-1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Single Sign-On (SSO) mechanism of Synology DiskStation Manager (DSM) versions before 7.2.2-72806-5 and 7.3.1-86003-1. It is caused by an improper check for unusual or exceptional conditions, which allows remote attackers to bypass authentication if they have prior knowledge of the distinguished name (DN). This means an attacker can gain unauthorized access without proper credentials by exploiting this flaw.


How can this vulnerability impact me? :

The impact of this vulnerability is significant because it allows remote attackers to bypass authentication controls, potentially gaining full access to the affected Synology DiskStation Manager system. This can lead to unauthorized access to sensitive data, full control over the system, and the ability to perform actions with high privileges, affecting confidentiality, integrity, and availability.


How can this vulnerability be detected on my network or system? Can you suggest some commands?

There are no specific detection methods or commands provided in the available information to identify this vulnerability on your network or system.


What immediate steps should I take to mitigate this vulnerability?

The recommended immediate step to mitigate this vulnerability is to upgrade Synology DiskStation Manager (DSM) to version 7.3.1-86003-1 or later if you are using DSM 7.3, or to version 7.2.2-72806-5 or later if you are using DSM 7.2.2.

No other mitigation steps beyond applying these updates have been provided.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart