First published: Wed Apr 09 2025(Updated: )
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BeeStation BST150-4T devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2024-50631.
Affected Software | Affected Version | How to fix |
---|---|---|
Synology BeeStation BST150-4T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ZDI-25-213 has been assigned a CVSS rating of 6.4.
ZDI-25-213 allows network-adjacent attackers to execute arbitrary code on affected Synology BeeStation BST150-4T devices.
Yes, authentication is required to exploit the vulnerability ZDI-25-213.
ZDI-25-213 affects installations of Synology BeeStation BST150-4T devices.
Mitigation strategies for ZDI-25-213 include ensuring proper user authentication and updating to the latest firmware.