ZDI-CAN-28485: ZDI-26-424: Synology DiskStation DS925+ MailPlus Improper Restriction of Communication Channel to Intended Endpoints Vulnerability
Published Jul 15, 2026
·Updated
This vulnerability allows network-adjacent attackers to access the Redis instance on affected installations of Synology DiskStation DS925+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2026-13135.
Affected Software
1 affected component
Synology DiskStation DS925+
Event History
Jul 15, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28485?
The CVSS rating for ZDI-CAN-28485 is 4.3, indicating moderate severity.
2
How do I fix ZDI-CAN-28485?
To fix ZDI-CAN-28485, ensure that the Redis instance is properly secured and restrict access to intended endpoints.
3
What type of vulnerability is ZDI-CAN-28485?
ZDI-CAN-28485 is classified as an improper restriction of communication channel to intended endpoints vulnerability.
4
Who is affected by ZDI-CAN-28485?
ZDI-CAN-28485 affects installations of Synology DiskStation DS925+ devices.
5
Is authentication required to exploit ZDI-CAN-28485?
No, authentication is not required to exploit ZDI-CAN-28485.