← back
CVE-2016-6554CWE-255

Synology NAS servers DS107, DS116, and DS213, use default credentials

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 4.1%
exploitation probability
4.1%top 10% of all CVEs
observed exploitation
nono source reports it
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.