CVE-2016-6554

Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.
References
Link Resource
https://www.kb.cert.org/vuls/id/404187 Third Party Advisory US Government Resource
https://www.securityfocus.com/bid/93805 Third Party Advisory VDB Entry
https://www.synology.com/en-global/releaseNote/DS213 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:synology:ds107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:ds107:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:synology:ds213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:ds213:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:synology:ds116_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:ds116:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-07-13 20:29

Updated : 2023-12-10 12:44


NVD link : CVE-2016-6554

Mitre link : CVE-2016-6554

CVE.ORG link : CVE-2016-6554


JSON object : View

Products Affected

synology

  • ds213_firmware
  • ds213
  • ds116_firmware
  • ds107
  • ds116
  • ds107_firmware
CWE
CWE-255

Credentials Management Errors