Main
Vulnerability Database
Exploits
ID:12181 - Exploit for Improper Encoding or Escaping of Output in DiskStation Manager (DSM) - CVE-2024-50629
ID:12181 - Exploit for Improper Encoding or Escaping of Output in DiskStation Manager (DSM) - CVE-2024-50629
Published: December 4, 2025
Vulnerability identifier: #VU107357
Vulnerability risk: Medium
CVE-ID: CVE-2024-50629
CWE-ID: CWE-116
Exploitation vector: Remote access
Vulnerable software:
DiskStation Manager (DSM)
DiskStation Manager (DSM)
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper encoding or escaping of output in the webapi component. A remote attacker can read limited files on the system.
Remediation
Install updates from vendor's website.