ZDI-CAN-25613: ZDI-25-211: (Pwn2Own) Synology BeeStation BST150-4T CRLF Injection Information Disclosure Vulnerability
Published Apr 9, 2025
·Updated
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Synology BeeStation BST150-4T devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-50629.
Affected Software
1 affected component
Synology BeeStation BST150-4T
Event History
Apr 9, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-25613?
The severity of ZDI-CAN-25613 is rated at 6.5 according to the CVSS scoring system.
2
What devices are affected by ZDI-CAN-25613?
ZDI-CAN-25613 affects Synology BeeStation BST150-4T devices.
3
Is authentication required to exploit ZDI-CAN-25613?
No, authentication is not required to exploit ZDI-CAN-25613.
4
What type of attack does ZDI-CAN-25613 involve?
ZDI-CAN-25613 allows network-adjacent attackers to disclose sensitive information.
5
How can organizations mitigate the risk of ZDI-CAN-25613?
Organizations can mitigate the risk of ZDI-CAN-25613 by applying security patches and securing network access to affected devices.