Operating systems
Rewards of up to
US $30,000
Includes Synology DiskStation Manager, Synology Router Manager, and Synology BeeStation.
Software and C2 cloud services
Rewards of up to
US $10,000
Includes Synology-developed software packages, related mobile apps, and C2 cloud services.
Web services
Rewards of up to
US $5,000
Includes all major Synology web services.
- You are the first researcher to report this vulnerability
- The reported vulnerability is confirmed to be verifiable, replicable, and a valid security issue
- Your report complies with the Bounty Program’s terms and regulations
Contact us using the Bounty Program contact form.
Use this PGP key to encrypt your information when sending bug reports to Synology.
Include a detailed proof of concept (PoC) and make sure that the reported issues can be reproduced.
Keep your description succinct. For example, a short proof-of-concept link is valued higher than a video explaining the consequences of an SSRF issue.
- Contain a clearly written step-by-step description in English of how to reproduce the vulnerability
- Demonstrate how the vulnerability affects Synology products or web services, and describe which versions and platforms are affected
- State the potential damage caused by the reported vulnerability
Reward | Qualified reports are eligible for a reward of up to US$30,000.* |
---|---|
Products within scope | Only reports about officially released versions are accepted. DiskStation Manager (DSM)
Synology Router Manager (SRM)**
Synology Camera firmware***
Synology BeeStation
|
Regulations and restrictions | This program is strictly limited to security vulnerabilities found in Synology products and services. Actions that could potentially damage or detrimentally affect Synology servers or data are strictly forbidden. Vulnerability testing must not breach local or Taiwanese laws. Vulnerability reports are not accepted under the program if they describe or involve:
|
**The maximum reward for vulnerabilities in SRM_LAN is $5,000.
***The maximum reward for vulnerabilities in camera firmware is $10,000.
Reward | Qualified reports are eligible for a reward of up to US$10,000.* |
---|---|
Products within scope | Only reports about officially released versions are accepted. Packages Synology-developed software packages Desktop clients Synology-developed Windows, macOS, and Linux applications Mobile apps Synology-developed mobile apps for Android and iOS Synology Account
C2 services *.c2.synology.com domains |
Regulations and restrictions | This program is strictly limited to security vulnerabilities found in Synology products and services. Actions that could potentially damage or detrimentally affect Synology servers or data are strictly forbidden. Vulnerability testing must not breach local or Taiwanese laws. Vulnerability reports are not accepted under the program if they describe or involve:
|
Reward | Qualified reports are eligible for a reward of up to US$5,000.* |
---|---|
Products within scope | The following domains (including sub-domains) are in scope: *.synology.com The following domains (including sub-domains) are out of scope: openstack-ci-logs.synology.com, router.synology.com, order.synology.com Synology reserves the right to modify this list at any time without notice. |
Regulations and restrictions | This program is strictly limited to security vulnerabilities found in Synology products and services. Actions that could potentially damage or detrimentally affect Synology servers or data are strictly forbidden. Vulnerability testing must not breach local or Taiwanese laws. Vulnerability reports are not accepted under the program if they describe or involve:
|
Operating systems | Software and C2 cloud services | Web services | |
---|---|---|---|
Zero-click pre-auth RCE | $30,000 | $10,000 | $5,000 |
Zero-click pre-auth arbitrary file r/w | $9,000 | $4,600 | $2,400 |
Operating systems | Software and C2 cloud services | Web services | |
---|---|---|---|
1-click pre-auth RCE | $8,000 | $4,000 | $2,000 |
Zero-click normal-user-auth RCE | $7,500 | $3,900 | $1,900 |
Zero-click normal-user-auth arbitrary file r/w | $6,500 | $3,400 | $1,700 |
Zero-click pre-auth RCE (AC:H) | $6,500 | $3,400 | $1,700 |
1-click pre-auth RCE (AC:H) | $5,000 | $2,500 | $1,325 |
pre-auth SQL injection | $3,800 | $1,950 | $1,025 |
1-click normal-user-auth RCE (AC:H) | $2,600 | $1,350 | $725 |
pre-auth stored XSS | $2,600 | $1,350 | $725 |
Operating systems | Software and C2 cloud services | Web services | |
---|---|---|---|
normal-user-auth stored XSS | $1,350 | $733 | $417 |
normal-user-auth SQL injection | $1,200 | $607 | $353 |
admin-auth vulnerabilities | $100 | $100 | $100 |
- Beginning October 1, 2024 admin-auth vulnerability rewards will be set at $100 USD.
- For Desktop Clients, if the CVSS vector includes any of the following, the reward is set to $100 USD:
- AV:L
- AV:A
- AV:N/AC:H
Notes:
- Please note that while guidelines for rewards are provided, each report is treated individually and thoroughly evaluated. Scoring considers various factors, including but not limited to the scope detailed in the rewards rubric. Synology reserves the right to final interpretation of the reward amounts.
- For issues classified as low severity or suggestions, only acknowledgements will be provided.
- Khoadha from VCSLab of Viettel Cyber Security ( https://viettelcybersecurity.com/)
- Tim Coen (https://security-consulting.icu/)
- Mykola Grymalyuk from RIPEDA Consulting
- Zhao Runzi (赵润梓)
- Andrea Maugeri (https://www.linkedin.com/in/andreamaugeri)
- Offensive Security Research @ Ronin (https://ronin.ae/)
- Nathan (Yama) https://DontClickThis.run
- M Tayyab Iqbal (www.alphainferno.com)
- Only Hack in Cave (tr4ce(Jinho Ju), neko_hat(Dohwan Kim), tw0n3(Han Lee), Hc0wl(GangMin Kim)) (https://github.com/Team-OHiC)
- Wonbeen Im, STEALIEN (https://stealien.com)
- 赵润梓、李建申(https://lsr00ter.github.io)
- Cheripally Sathwik (https://www.instagram.com/ethical_hacker_sathwik)
- Steven Lin (https://x.com/5teven1in)
- Qian Chen (@cq674350529) from Codesafe Team of Legendsec at QI-ANXIN Group
- Mohd Ali (revengerali)
- Orange Tsai (@orange_8361) from DEVCORE Research Team
- Bocheng Xiang with FDU(@crispr)
- HANRYEOL PARK, HYOJIN LEE, HYEOKJONG YUN, HYEONJUN LEE, DOWON KWAK, ZIEN (https://zi-en.io/)
- Hydrobikz (https://www.linkedin.com/in/bikash-)
- Can Acar (https://imcan.dev)
- Yves Bieri of Compass Security (https://www.compass-security.com)
- DEVCORE Research Team (https://devco.re/)
- aoxsin (https://twitter.com/aoxsin)