#VU125951 Files or Directories Accessible to External Parties in SSL VPN Client - CVE-2021-47960
Published: April 14, 2026
SSL VPN Client
Synology Inc.
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to files or directories accessible to external parties in the local HTTP service bound to the loopback interface when handling requests from a crafted web page. A remote attacker can trick the victim into interacting with a crafted web page to disclose sensitive information.
User interaction is required, and exposed files may include configuration files, certificates, and logs from the installation directory.