CVE-2024-10443
massUnauthenticated OS Command Injection RCE in Synology Photos and BeePhotos
CVE-2024-10443 is an OS command injection flaw (CWE-78) in the Task Manager component of Synology Photos and Synology BeePhotos that allows remote, unauthenticated attackers to execute arbitrary code on the NAS via unspecified vectors. Because the vector requires no privileges and no user interaction (AV:N/PR:N per the CVSS 9.8 score), press coverage describes it as a zero-click RCE affecting internet-facing Synology NAS devices. An attacker who successfully exploits it gains full code execution on the device, typically with access to data stored on the NAS. Users running Synology Photos before 1.6.2-0720 / 1.7.0-0795 or BeePhotos before 1.0.2-10026 / 1.1.0-10053 are affected. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but the high EPSS score (28% within 30 days, 98th percentile) indicates a high predicted risk of imminent exploitation.
What to do: Upgrade Synology Photos to 1.6.2-0720 or 1.7.0-0795 (or later) and BeePhotos to 1.0.2-10026 or 1.1.0-10053 (or later) as soon as possible. Until patched, limit exposure by disabling external/QuickConnect access to the Photos/BeePhotos services and removing port-forwarding rules to the NAS web interface. Check DSM logs for unexpected processes or network connections, and inventory all NAS units, since exploitation requires no authentication or user interaction.
| Synology Photos | all versions before 1.6.2-0720 (1.6.x line) and before 1.7.0-0795 (1.7.x line) |
| Synology BeePhotos | all versions before 1.0.2-10026 (1.0.x line) and before 1.1.0-10053 (1.1.x line) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
- Vendors
- synology
- Products
- photos, beephotos
- Weakness
- CWE-78, CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H