PT-2025-11656 · Synology · Synology Camera Firmware

Published

2025-03-19

·

Updated

2025-04-09

·

CVE-2024-11131

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology Camera Firmware versions prior to 1.2.0-0525
Description A vulnerability regarding out-of-bounds read is found in the video interface, allowing remote attackers to execute arbitrary code via unspecified vectors. The affected models include BC500, CC400W, and TC500.
Recommendations For Synology Camera Firmware versions prior to 1.2.0-0525, update the firmware to version 1.2.0-0525 or later to resolve the issue. As a temporary workaround, consider restricting access to the video interface until a patch is available.

Fix

RCE

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2024-11131
ZDI-25-216

Affected Products

Synology Camera Firmware