Synology fixed critical flaw impacting millions of DiskStation and BeePhotos NAS devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-10443 | Unauthenticated OS Command Injection RCE in Synology Photos and BeePhotos CVE-2024-10443 is an OS command injection flaw (CWE-78) in the Task Manager component of Synology Photos and Synology BeePhotos that allows remote, unauthenticated attackers to execute arbitrary code on the NAS via unspecified vectors. Because the vector requires no privileges and no user interaction (AV:N/PR:N per the CVSS 9.8 score), press coverage describes it as a zero-click RCE affecting internet-facing Synology NAS devices. An attacker who successfully exploits it gains full code execution on the device, typically with access to data stored on the NAS. Users running Synology Photos before 1.6.2-0720 / 1.7.0-0795 or BeePhotos before 1.0.2-10026 / 1.1.0-10053 are affected. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but the high EPSS score (28% within 30 days, 98th percentile) indicates a high predicted risk of imminent exploitation. Do: Upgrade Synology Photos to 1.6.2-0720 or 1.7.0-0795 (or later) and BeePhotos to 1.0.2-10026 or 1.1.0-10053 (or later) as soon as possible. Until patched, limit exposure by disabling external/QuickConnect access to the Photos/BeePhotos services and removing port-forwarding rules to the NAS web interface. Check DSM logs for unexpected processes or network connections, and inventory all NAS units, since exploitation requires no authentication or user interaction. | 9.8 | 28% |
| massmillions of NAS devices (press reports cite millions of vulnerable Synology DiskStation and BeePhotos units) |
Full article390 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 06, 2024

Synology addressed a critical vulnerability in DiskStation and BeePhotos NAS devices that could lead to remote code execution.
Taiwanese vendor Synology has addressed a critical security vulnerability, tracked as CVE-2024-10443, that impacts DiskStation and BeePhotos. An attacker can exploit the flaw without any user interaction and successful exploitation of this flaw could lead to remote code execution.
Security researcher Rick de Jager demonstrated the vulnerability, called RISK:STATION by cybersecurity firm Midnight Blue, at the Pwn2Own Ireland 2024 hacking contest.
Midnight Blue took 3rd at Pwn2Own Ireland 2024, the team demonstrated five zero-day flaws in routers, printers, security cameras, and NAS devices. Among these was RISK:STATION, a zero-click flaw that enables root-level access on Synology NAS devices like DiskStation, impacting millions. Synology quickly addressed the vulnerability within 48 hours after notification, but, given the risk, urged users to apply updates immediately.
“One of these vulnerabilities is RISK:STATION, an unauthenticated zero-click vulnerability allowing attackers to obtain root-level code execution on the popular Synology DiskStation and BeeStation NAS devices, affecting millions of devices.” reads the report published by Midnightblue. “The vulnerability was initially discovered, within just a few hours, as a replacement for another Pwn2Own submission. The issue was disclosed to Synology immediately after demonstration, and within 48 hours a patch was made available which resolves the vulnerability. Official guidance from Synology can be found on their advisories page. However, since the vulnerability has a high potential for criminal abuse, and millions of devices are affected, a media reach-out was made to inform system owners of the issue and to stress the point that immediate mitigative actions are required.”
Below is the list of affected versions:
- BeePhotos for BeeStation OS 1.0 (Upgrade to 1.0.2-10026 or above)
- BeePhotos for BeeStation OS 1.1 (Upgrade to 1.1.0-10053 or above)
- Synology Photos 1.6 for DSM 7.2 (Upgrade to 1.6.2-0720 or above)
- Synology Photos 1.7 for DSM 7.2 (Upgrade to 1.7.0-0795 or above)
Taiwanese manufacturer QNAP also patched three zero-day vulnerabilities that were exploited by security researchers during the recent Pwn2Own Ireland 2024.
Technical details of the RISK:STATION vulnerability remain under embargo to prevent abuse. Midnight Blue assumes all Synology firmware versions before the patch are vulnerable, so users should apply the patch immediately.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Synology)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170602/hacking/synology-fixed-critical-bug-in-diskstation-and-beephotos-nas.html