HomeSecuritySynology fixes holes in its NAS devices

Synology patches holes in its NAS devices

synology-nas

Network-attached storage (NAS) company Synology has fixed several software issues in its devices, one of the bugs that was fixed could have allowed attackers to access stored data.

The most serious vulnerability was found in Photo Station , a feature of DiskStation Manager (DSM), the Linux- based operating system running on the company's NAS devices

Synologyallows 's Photo Station users to create online photo albums and blogs, which users can access remotely using the NAS device 's public IP address .

Researchers at Dutch company Securify discovered that Photo Station does not properly sanitize user input , allowing potential hackers to enter system commands that will be executed with Web server privileges.

Additionally, Photo Station does not have protection against cross-site request forgery (CSRF), a technique that allows a website to force browser to perform malicious actions on another site.

So even if Photo Station is not configured to be accessible from the web, an attacker could mislead a user on the same network as the NAS device and direct them to visit a specially crafted website that would use the CSRF technique and exploit the vulnerability by entering the command via the LAN.

By exploiting this hole, attackers can compromise the NAS device, including all the data on it, the researchers said in their report, which also includes the proof of concept exploit.

The company patched the security hole last week in Photo Station version 6.3-2945. However, the release notes only mention the phrase “security improvements” without further details.

The new version addresses two more cross-site scripting (XSS) vulnerabilities, identified by security researchers.

These holescan be exploited by tricking users of the program into opening a specially crafted URL, which will execute malicious code in their browsers . Successful attacks would allow attackers to steal the session tokens or log-in credentials of targeted users, as well as perform arbitrary actions on their behalf.

A similar vulnerability was also patched last week in the DiskStation Manage interface . Users are encouraged to update to the new version 5.2-5565 Update 1.

Synology NAS devices have been targeted by hackers in the past. Just last year, attackers exploited a vulnerability that affected many of these devices with a file-encrypting ransomware program, and hackers have previously targeted the company's devices by running cryptocurrency. miner programs on them

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS