Synology.BSM.DSM.RedirectURI.Information.Disclosure

description-logoDescription

This indicates an attack attempt to exploit an Information Disclosure Vulnerability in Synology BeeStation OS (BSM) and DiskStation Manager (DSM).
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted request. A remote attacker can exploit this to gain unauthorized access to sensitive information.

affected-products-logoAffected Products

Synology BeeStation OS (BSM) before 1.1-65374
Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1

Impact logoImpact

Information Disclosure: attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://www.synology.com/en-global/security/advisory/Synology_SA_24_20

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2026-02-05 35.164
Modified
Default_action:pass:drop
2026-01-27 35.158
New