← back
CVE-2020-27658highCWE-1004

CVE-2020-27658

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 1.3%
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
nono source reports it
In short

Synology Router Manager fails to protect its session cookie from being read by JavaScript code running in a browser. This allows attackers to steal the cookie and hijack user sessions.

Technical detail

The session cookie in SRM versions before 1.2.4-8081 lacks the HTTPOnly flag, enabling JavaScript-based XSS attacks to exfiltrate the cookie. Remote attackers can exploit this via malicious scripts to gain unauthorized session access, assuming the victim browses a compromised or attacker-controlled page while authenticated.

Summary generated and translated by AI from the official description.
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L