ZeroHour

CVE-2024-10443

mass

Unauthenticated OS Command Injection RCE in Synology Photos and BeePhotos

CVSS 3.1
9.8 critical
EPSS
28%p98
Published
()
Modified
AI analysis

CVE-2024-10443 is an OS command injection flaw (CWE-78) in the Task Manager component of Synology Photos and Synology BeePhotos that allows remote, unauthenticated attackers to execute arbitrary code on the NAS via unspecified vectors. Because the vector requires no privileges and no user interaction (AV:N/PR:N per the CVSS 9.8 score), press coverage describes it as a zero-click RCE affecting internet-facing Synology NAS devices. An attacker who successfully exploits it gains full code execution on the device, typically with access to data stored on the NAS. Users running Synology Photos before 1.6.2-0720 / 1.7.0-0795 or BeePhotos before 1.0.2-10026 / 1.1.0-10053 are affected. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but the high EPSS score (28% within 30 days, 98th percentile) indicates a high predicted risk of imminent exploitation.

What to do: Upgrade Synology Photos to 1.6.2-0720 or 1.7.0-0795 (or later) and BeePhotos to 1.0.2-10026 or 1.1.0-10053 (or later) as soon as possible. Until patched, limit exposure by disabling external/QuickConnect access to the Photos/BeePhotos services and removing port-forwarding rules to the NAS web interface. Check DSM logs for unexpected processes or network connections, and inventory all NAS units, since exploitation requires no authentication or user interaction.

Affected
Synology Photosall versions before 1.6.2-0720 (1.6.x line) and before 1.7.0-0795 (1.7.x line)
Synology BeePhotosall versions before 1.0.2-10026 (1.0.x line) and before 1.1.0-10053 (1.1.x line)
Estimated exposure
massmillions of NAS devices (press reports cite millions of vulnerable Synology DiskStation and BeePhotos units) — Synology DiskStation NAS units running Synology Photos have an extremely large installed base and multiple news reports of this CVE explicitly describe millions of affected DiskStation and BeePhotos devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.

Vendors
synology
Products
photos, beephotos
Weakness
CWE-78, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news