PT-2024-28464 · Synology · Synology Camera Firmware

Published

2024-06-28

·

Updated

2025-03-04

·

CVE-2024-39349

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology Camera Firmware versions prior to 1.0.7-0298
Description A buffer copy issue without size checking, known as a 'Classic Buffer Overflow', exists in the libjansson component of the Synology Camera Firmware. This issue allows remote attackers to execute arbitrary code via unspecified vectors. The affected models include BC500 and TC500.
Recommendations For Synology Camera Firmware versions prior to 1.0.7-0298, update to version 1.0.7-0298 or later to resolve the issue. As a temporary workaround, consider restricting access to the synocam param.cgi endpoint until the update is applied.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39349
ZDI-24-833

Affected Products

Synology Camera Firmware