ZDI-CAN-25663: ZDI-25-269: (Pwn2Own) Synology BeeStation BST150-4T Unnecessary Privileges Remote Code Execution Vulnerability
Published May 1, 2025
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BeeStation BST150-4T devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2024-10445.
Affected Software
1 affected component
Synology BeeStation BST150-4T
Event History
May 1, 2025
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-25663?
The severity of ZDI-CAN-25663 is rated at 5.3 on the CVSS scale.
2
How do I fix ZDI-CAN-25663?
To fix ZDI-CAN-25663, ensure that you apply the latest firmware updates provided by Synology for the BeeStation BST150-4T.
3
What type of attackers can exploit ZDI-CAN-25663?
Network-adjacent attackers can exploit ZDI-CAN-25663 without requiring authentication.
4
What devices are affected by ZDI-CAN-25663?
ZDI-CAN-25663 affects the Synology BeeStation BST150-4T devices.
5
Can ZDI-CAN-25663 lead to remote code execution?
Yes, ZDI-CAN-25663 allows attackers to execute arbitrary code on the affected installations.