ZDI-CAN-25617: ZDI-25-209: (Pwn2Own) Synology BeeStation BST150-4T Cleartext Transmission of Sensitive Information Vulnerability
This vulnerability allows network-adjacent attackers to spoof specific configuration values on affected installations of Synology BeeStation BST150-4T devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2024-10445.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25617?
The severity of ZDI-CAN-25617 has been rated at 4.3 on the CVSS scale.
How do I fix ZDI-CAN-25617?
To fix ZDI-CAN-25617, ensure that your Synology BeeStation BST150-4T device is updated to the latest firmware version provided by Synology.
Who is affected by ZDI-CAN-25617?
ZDI-CAN-25617 affects installations of the Synology BeeStation BST150-4T device.
Is authentication required to exploit ZDI-CAN-25617?
No, authentication is not required to exploit ZDI-CAN-25617.
What type of attack does ZDI-CAN-25617 enable?
ZDI-CAN-25617 allows network-adjacent attackers to spoof specific configuration values on affected devices.