ZDI-25-208: (Pwn2Own) Synology DiskStation DS1823xs+ Replication Service Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Apr 9, 2025
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation DS1823xs+ devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-10442.
Affected Software
1 affected component
Synology DiskStation DS1823xs+
Event History
Apr 9, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-208?
The severity of ZDI-25-208 is rated at 7.5 on the CVSS scale.
2
How do I fix ZDI-25-208?
To fix ZDI-25-208, apply the latest security patch provided by Synology for the DiskStation DS1823xs+.
3
What is the impact of ZDI-25-208?
ZDI-25-208 allows network-adjacent attackers to execute arbitrary code on affected systems without authentication.
4
Who is affected by ZDI-25-208?
ZDI-25-208 affects installations of Synology DiskStation DS1823xs+ devices.
5
Is authentication required to exploit ZDI-25-208?
No, authentication is not required to exploit ZDI-25-208.