Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
affected
1.3 (semver) before 1.3.2-65648
affected
1.2 (semver) before 1.3.2-65648
affected
1.1 (semver) before 1.3.2-65648
affected
1.0 (semver) before 1.3.2-65648
affected
Any version before 1.0
unknown
Description
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
1.3 (semver) before 1.3.2-65648
1.2 (semver) before 1.3.2-65648
1.1 (semver) before 1.3.2-65648
1.0 (semver) before 1.3.2-65648
Any version before 1.0
Credits
@Tek_7987 & @_Anyfun (@Synacktiv)
References
www.synology.com/...obal/security/advisory/Synology_SA_25_12 (Synology-SA-25:12 BeeStation (PWN2OWN 2025))