Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and pathname options.
Conclusion & alert: CVE-2021-26567 is rated Moderate Risk (57.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.13%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-07-30 | 1.65% | 1.13% | -0.52% |
| 2 | 2025-03-30 | 2.96% | 1.65% | -1.30% |
| 3 | 2025-03-29 | — | 2.96% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 6.5 | 2.0 | MEDIUM |
|
8.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| synology | diskstation_manager | < 6.2.3-25426-3 | cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* |
| synology | vs960hd_firmware | — | cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:* |
| synology | skynas_firmware | — | cpe:2.3:o:synology:skynas_firmware:-:*:*:*:*:*:*:* |
| synology | diskstation_manager_unified_controller | 3.0 | cpe:2.3:o:synology:diskstation_manager_unified_controller:3.0:*:*:*:*:*:*:* |
| faad2_project | faad2 | < 2.2.7.1 | cpe:2.3:a:faad2_project:faad2:*:*:*:*:*:*:*:* |