PT-2025-11656 · Synology · Synology Camera Firmware

CVE-2024-11131

·

Published

2025-03-19

·

Updated

2025-04-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology Camera Firmware versions prior to 1.2.0-0525
Description A vulnerability regarding out-of-bounds read is found in the video interface, allowing remote attackers to execute arbitrary code via unspecified vectors. The affected models include BC500, CC400W, and TC500.
Recommendations For Synology Camera Firmware versions prior to 1.2.0-0525, update the firmware to version 1.2.0-0525 or later to resolve the issue. As a temporary workaround, consider restricting access to the video interface until a patch is available.

Fix

RCE

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11131
ZDI-25-216

Affected Products

Synology Camera Firmware