Router Manager
59 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Router Manager, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Router Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 8 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 3 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 4 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 59 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High19
- Medium35
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Router Manager.
- CVE-2025-29846A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.7.2
- CVE-2025-29845A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.4.3
- CVE-2025-29844A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.4.3
- CVE-2025-29843A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.5.4
- CVE-2024-53288Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote au...5.9
- CVE-2024-53287Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote a...5.9
- CVE-2024-53286Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows re...7.2
- CVE-2024-53285Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote a...5.9
- CVE-2024-53284Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows...5.9
- CVE-2024-53283Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forward functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows ...5.9
- CVE-2024-53282Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC Filter functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 all...5.9
- CVE-2024-53281Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote a...5.9
- CVE-2024-53279Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote ...5.9
- CVE-2024-53280Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center policy route functionality in Synology Router Manager (SRM) before 1.3.1-9346-10...5.9
- CVE-2024-11398Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote authentica...8.1
Product grouping is registry-driven, with AI assist and human review. How it works