logo

CVE-2024-10443

ID: eabe6044-da8c-56a6-9312-f0f48d927203

STIX ID: report--eabe6044-da8c-56a6-9312-f0f48d927203

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2024-11-04

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs warns of CVE-2024-10443, a zero-click RCE in Synology Photos and BeePhotos that can allow unauthenticated remote root access on internet-exposed NAS devices (potentially hundreds of thousands to millions affected). Synology has released fixes; Arctic Wolf recommends upgrading to the fixed versions and, where appropriate, disabling QuickConnect for the Photo application while noting no observed active exploitation to date but a high likelihood of threat actors — including ransomware groups — attempting to reverse-engineer patches and exploit the flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.