CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 40.8% probability of exploitation in the next 30 days. It may be remotely exploitable.
CVE
CVE-2016-10329
Severity
CRITICAL
CVSS
9.8
EPSS
40.81%
Original NVD Description
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.
Related CVEs
Other vulnerabilities affecting the same vendor(s)