ID:12181 - Exploit for Improper Encoding or Escaping of Output in DiskStation Manager (DSM) - CVE-2024-50629

 
Main Vulnerability Database Exploits ID:12181 - Exploit for Improper Encoding or Escaping of Output in DiskStation Manager (DSM) - CVE-2024-50629

ID:12181 - Exploit for Improper Encoding or Escaping of Output in DiskStation Manager (DSM) - CVE-2024-50629

Published: December 4, 2025


Vulnerability identifier: #VU107357
Vulnerability risk: Medium
CVE-ID: CVE-2024-50629
CWE-ID: CWE-116
Exploitation vector: Remote access
Vulnerable software:
DiskStation Manager (DSM)

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper encoding or escaping of output in the webapi component. A remote attacker can read limited files on the system.


Remediation

Install updates from vendor's website.