CVE-2025-13392

Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote attackers to bypass authentication with prior knowledge of the distinguished name (DN).
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

History

02 Jun 2026, 20:42

Type Values Removed Values Added
First Time Synology
Synology diskstation Manager
References () https://www.synology.com/en-global/security/advisory/Synology_SA_25_14 - () https://www.synology.com/en-global/security/advisory/Synology_SA_25_14 - Vendor Advisory
CPE cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*

27 May 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 09:16

Updated : 2026-06-02 20:42


NVD link : CVE-2025-13392

Mitre link : CVE-2025-13392

CVE.ORG link : CVE-2025-13392


JSON object : View

Products Affected

synology

  • diskstation_manager
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions