By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland
Tech News

Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland

By admin 3 Min Read
Share
SHARE

Synology has addressed a critical-severity remote code execution (RCE) vulnerability in BeeStation products that was demonstrated at the recent Pwn2Own hacking competition.

The security issue (CVE-2025-12686) is described as a ‘buffer copy without checking the size of input’ problem, and can be exploited to allow arbitrary code execution.

It impacts multiple versions of BeeStation OS, the software powering Synology’s network-attached storage (NAS) devices marketed as a consumer-oriented  “personal cloud.”

Wiz

There are no mitigations available, so the vendor recommends that users upgrade to the following versions, which address :

  • BeeStation OS version 1.3.2-65648 or above
  • BeeStation OS version 1.3.2-65648 or above
  • BeeStation OS version 1.3.2-65648 or above
  • BeeStation OS version 1.3.2-65648 or above

Researchers Tek and anyfun at French cybersecurity company Synacktiv exploited the flaw in a demonstration during the Pwn2Own Ireland 2025 contest on October 21st. For their successful exploitation, the two researchers received a $40,000 reward.

tweet

A three-day hacking competition organized by Trend Micro and the Zero Day Initiative (ZDI), Pwn2Own gives security researchers the opportunity to hack popular consumer devices using zero-day vulnerabilities.

The most recent event held in Ireland had researchers demonstrating 73 zero-day flaws across a broad range of products and winning more than $1 million.

Last week, another major NAS vendor, QNAP, fixed a total of seven zero-day vulnerabilities in multiple devices from the company, which white-hat hackers had shown at Pwn2Own Ireland this year.

ZDI has a disclosure agreement with companies participating in Pwn2Own and holds off publishing the technical details of the security issues until patches are available and users have had sufficient time to apply the updates.

More details about these flaws will be disclosed in the coming months on ZDI’s bulletin board and, in some cases, on personal blog spaces of the researchers themselves.

Wiz

As MCP (Model Context Protocol) becomes the standard for connecting LLMs to tools and data, security teams are moving fast to keep these new services safe.

This free cheat sheet outlines 7 best practices you can start using today.

You Might Also Like

Research Ireland awards €4.4m to 46 enterprise-engaged projects

Phone Fold Leaks: $1,999 Price, Release Date, and Specs

Google Just Made the Pixel 10a Look Even More Stupid

Artemis II Countdown: How and When to Watch the Launch

GIGABYTE Control Center vulnerable to arbitrary file write flaw

TAGGED: Buffer Overflow, Remote Code Execution, Synology, Vulnerability, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article Colombia to suspend intelligence cooperation with US over strikes on drug vessels
Next Article The Nike x Hyperice Hyperboot Is $200 Off
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Sheryl Sandberg tapped a 25-year-old to run Lean In. Here’s her plan to close the AI gender gap
Business
E-commerce giant MercadoLibre to sunset rewards-based Mercado Coin: Report
Crypto
Washington Becomes Latest Democrat-Led State to Tax Millionaires, Sparking Legal Fight
Politics
Blizzard reveals Overwatch's next hero, a Damage-class mystery character
Gaming News
Research Ireland awards €4.4m to 46 enterprise-engaged projects
Tech News
Should you book holiday flights now considering jet fuel price spikes?
Business
US wrong to negotiate, Iranian regime ‘not trustworthy,’ Iranian opposition leader says
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Sheryl Sandberg tapped a 25-year-old to run Lean In. Here’s her plan to close the AI gender gap

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Sheryl Sandberg tapped a 25-year-old to run Lean In. Here’s her plan to close the AI gender gap
April 1, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?