PT-2024-7608 · Synology · Synology Beephotos+1

Rick De Jager

·

Published

2024-10-25

·

Updated

2026-03-27

·

CVE-2024-10443

CVSS v3.1

10

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology BeePhotos versions prior to 1.0.2-10026 Synology BeePhotos version 1.1.0-10053 Synology Photos versions prior to 1.6.2-0720 Synology Photos version 1.7.0-0795 Synology BeeStation BST150-4T (affected versions not specified)
Description A command injection flaw exists in the Task Manager component of Synology BeePhotos and Synology Photos. This issue allows remote attackers to execute arbitrary code without user interaction. Millions of Synology NAS devices are potentially affected. The vulnerability, dubbed RISK:STATION, was discovered at Pwn2Own 2024 and is actively exploited. The root cause is improper neutralization of special elements used in OS commands. The Task Manager component is vulnerable to this issue. The vulnerability allows attackers to execute arbitrary code via unspecified vectors.
Recommendations Update Synology BeePhotos to version 1.0.2-10026 or later. Update Synology BeePhotos to version 1.1.0-10053 or later. Update Synology Photos to version 1.6.2-0720 or later. Update Synology Photos to version 1.7.0-0795 or later.

Fix

RCE

OS Command Injection

Improper Privilege Management

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-09014
CVE-2024-10443
ZDI-25-207

Affected Products

Synology Beephotos
Synology Photos