Synology hurries out patches for zero-days exploited at Pwn2Own

Share:

Synology, a Taiwanese network-attached storage (NAS) appliance maker, patched two critical zero-days exploited during last week’s Pwn2Own hacking competition within days.

Midnight Blue security researcher Rick de Jager found the critical zero-click vulnerabilities (tracked together as CVE-2024-10443 and dubbed RISK:STATION) in the company’s Synology Photos and BeePhotos for BeeStation software.

As Synology explains in security advisories published two days after the flaws were demoed at Pwn2Own Ireland 2024 to hijack a Synology BeeStation BST150-4T device, the security flaws enable remote attackers to gain remote code execution as root on vulnerable NAS appliances exposed online.

“The vulnerability was initially discovered, within just a few hours, as a replacement for another Pwn2Own submission. The issue was disclosed to Synology immediately after demonstration, and within 48 hours a patch was made available which resolves the vulnerability,” Midnight Blue said.

“However, since the vulnerability has a high potential for criminal abuse, and millions of devices are affected, a media reach-out was made to inform system owners of the issue and to stress the point that immediate mitigative actions are required.”

Synology says it addressed the vulnerabilities in the following software releases; however, they’re not automatically applied on vulnerable systems, and customers are advised to update as soon as possible to block potential incoming attacks:

  • BeePhotos for BeeStation OS 1.1: Upgrade to 1.1.0-10053 or above
  • BeePhotos for BeeStation OS 1.0: Upgrade to 1.0.2-10026 or above
  • Synology Photos 1.7 for DSM 7.2: Upgrade to 1.7.0-0795 or above.
  • Synology Photos 1.6 for DSM 7.2: Upgrade to 1.6.2-0720 or above.

QNAP, another Taiwanese NAS device manufacturer, patched two more critical zero-days exploited during the hacking contest within a week (in the company’s SMB Service and Hybrid Backup Sync disaster recovery and data backup solution).

While Synology and QNAP hurried out security updates, vendors are given 90 days until Trend Micro’s Zero Day Initiative releases details on bugs disclosed during the contest and usually take their time to release patches.

This is likely because NAS devices are commonly used to store sensitive data by both home and enterprise customers, and they’re also often exposed to Internet access for remote access. However, this makes them vulnerable targets for cybercriminals who exploit weak passwords or vulnerabilities to breach the systems, steal data, encrypt files, and extort owners by demanding ransoms to provide access to the lost files.

As Midnight Blue security researchers who demoed the Synology zero-days during Pwn2Own Ireland 2024 told cybersecurity journalist Kim Zetter (who first reported on the security updates), they found Internet-exposed Synology NAS devices on the networks of police departments in the U.S. and Europe, as well as critical infrastructure contractors from South Korea, Italy, and Canada.

QNAP and Synology have warned customers for years that devices exposed online are being targeted by ransomware attacks. For instance, eCh0raix ransomware (also known as QNAPCrypt), which first surfaced in June 2016, has been targeting such systems regularly, with two large-scale ones reported in June 2019 (against QNAP and Synology devices) and in June 2020 standing out.

In more recent attack waves, threat actors have also used other malware strains (including DeadBolt and Checkmate ransomware) and various security vulnerabilities to encrypt Internet-exposed NAS devices.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:12 pm, Jun 28, 2025
weather icon 24°C
L: 22° | H: 25°
clear sky
Humidity: 71 %
Pressure: 1024 mb
Wind: 10 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 1%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:45 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
22° | 25°°C 0 mm 0% 7 mph 81 % 1026 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
20° | 34°°C 1 mm 100% 6 mph 66 % 1022 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
20° | 32°°C 0.77 mm 77% 11 mph 68 % 1019 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
16° | 24°°C 1 mm 100% 12 mph 89 % 1019 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
15° | 22°°C 0 mm 0% 15 mph 81 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 23°°C 0 mm 0% 7 mph 73 % 1024 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 20°°C 0 mm 0% 5 mph 80 % 1025 mb 0 mm/h
Tomorrow 7:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 81 % 1026 mb 0 mm/h
Tomorrow 10:00 am
weather icon
23° | 23°°C 0 mm 0% 4 mph 58 % 1026 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
28° | 28°°C 0 mm 0% 5 mph 43 % 1025 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 3 mph 35 % 1023 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
30° | 30°°C 0 mm 0% 1 mph 34 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
24° | 24°°C 0 mm 0% 6 mph 56 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,470.72
0.01%
Ethereum(ETH)
€2,074.15
0.18%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.86
3.29%
Solana(SOL)
€128.22
5.25%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139354
1.73%
Shiba Inu(SHIB)
€0.000010
2.07%
Pepe(PEPE)
€0.000008
3.41%
Scroll to Top