ZDI-CAN-25658: ZDI-25-212: (Pwn2Own) Synology BeeStation BST150-4T Improper Authentication Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Synology BeeStation BST150-4T devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-50630.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25658?
The CVSS rating for ZDI-CAN-25658 is 7.5, indicating a high severity vulnerability.
How does ZDI-CAN-25658 exploit authentication bypass?
ZDI-CAN-25658 allows network-adjacent attackers to bypass authentication without any requirements on affected Synology BeeStation BST150-4T devices.
Who is affected by ZDI-CAN-25658?
ZDI-CAN-25658 affects installations of the Synology BeeStation BST150-4T device.
Is authentication required to exploit ZDI-CAN-25658?
No, authentication is not required to exploit the ZDI-CAN-25658 vulnerability.
What type of devices does ZDI-CAN-25658 impact?
ZDI-CAN-25658 impacts Synology BeeStation BST150-4T devices specifically.