ZDI-CAN-25659: ZDI-25-213: (Pwn2Own) Synology BeeStation BST150-4T SQL Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BeeStation BST150-4T devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2024-50631.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25659?
The severity of ZDI-CAN-25659 is rated as 6.4 on the CVSS scale.
What does ZDI-CAN-25659 allow an attacker to do?
ZDI-CAN-25659 allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BeeStation BST150-4T devices.
Is authentication required to exploit ZDI-CAN-25659?
Yes, authentication is required to exploit the vulnerability identified as ZDI-CAN-25659.
Which devices are affected by ZDI-CAN-25659?
The vulnerability ZDI-CAN-25659 specifically affects Synology BeeStation BST150-4T devices.
How can I mitigate the risk of ZDI-CAN-25659?
To mitigate the risk of ZDI-CAN-25659, ensure that your Synology BeeStation BST150-4T device is updated with the latest security patches.