Improper Certificate Validation in DiskStation Manager (DSM) - CVE-2026-40539
Published: April 16, 2026
DiskStation Manager (DSM)
Detailed vulnerability description
The vulnerability allows a remote attacker to read or write arbitrary files and cause a denial of service.
The vulnerability exists due to improper certificate validation in DSM when establishing adjacent-network connections. A remote attacker can perform a man-in-the-middle attack to read or write arbitrary files and cause a denial of service.
User interaction is required.