NAS
Synology

Synology Synology DS218+

- The Synology DS218+ is a 2-bay NAS device designed for home and small business use, offering high-performance storage and advanced features.

Synology Synology DS218+

Specifications

OS
DiskStation Manager (DSM)
CPU
Intel Celeron J3355 dual-core 2.0 GHz
LAN
Gigabit Ethernet
RAM
2 GB DDR3L
USB
3x USB 3.0
WAN
No
Drive Bays
2

Potential Threats

3
Critical
8
High
12
Medium
2
Low

25 Known CVEs

3 critical vulnerabilities found — immediate patching required.
Disable default public shares. Enable disk encryption. Restrict access by IP and use strong per-user credentials.

Default IP

192.168.1.2

Default admin panel address for Synology Synology DS218+

Known CVE Vulnerabilities (25)

Sort:
CVE-2024-10442 2025

Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synolog...

10.0
CVE-2024-10441 2025

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskSt...

9.8
CVE-2024-10437 2024

The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deactivation due to a missing capabi...

4.3
CVE-2024-10436 2024

The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the...

8.8
CVE-2024-10440 2024

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify...

9.8
CVE-2024-10439 2024

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific...

5.3
CVE-2024-10438 2024

The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying...

7.5
CVE-2024-10435 2024

A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/trigger...

6.3
CVE-2024-10434 2024

A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Te...

8.8
CVE-2024-10433 2024

A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affected by this issue is some unknow...

3.5

Showing 10 of 25

FAQ

What is the default password for Synology Synology DS218+?

The most common default credentials for Synology Synology DS218+ are listed in the table above. Always change these immediately after setup.

What is the default username for Synology Synology DS218+?

The default username for Synology Synology DS218+ is typically "admin". The full list of default credentials including username, password, access type and port is shown in the table on this page.

How do I change the password on Synology Synology DS218+?

Log in to the admin panel using the default credentials listed above. Navigate to Administration → Password or System → Account settings. Enter the current password and set a new strong password. Save the changes.

How do I reset Synology Synology DS218+ to factory defaults?

Locate the Reset button (usually a small pinhole on the back/bottom of the device). Hold it for 10-30 seconds while powered on until the LEDs flash. The device will reboot with default settings.

Is it safe to leave default credentials unchanged?

No. Default credentials are publicly known and frequently exploited by automated scanners. Change the admin password immediately after first login.

Does Synology Synology DS218+ have known security vulnerabilities?

Synology Synology DS218+ has 25 known CVE vulnerabilities documented in our database. The full list with severity ratings is shown on this page. Apply the latest firmware update from the manufacturer to address known issues.

Related Devices