logo

Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland

ID: 2a44cb67-651a-5dee-a0ef-8f9d8bc624d2

STIX ID: report--2a44cb67-651a-5dee-a0ef-8f9d8bc624d2

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2025-11-11

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Synology released patches for a critical remote code execution vulnerability (CVE-2025-12686) in BeeStation OS powering its consumer NAS devices after researchers from Synacktiv exploited the flaw during Pwn2Own Ireland 2025; the issue is a buffer-copy without input size checks that allows arbitrary code execution and users are urged to upgrade to the fixed BeeStation OS versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.