Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Synology requires a patch for the critical Zero-Click RCE flaw affecting millions of NAS devices
Global Security

Synology requires a patch for the critical Zero-Click RCE flaw affecting millions of NAS devices

AdminBy AdminNovember 5, 2024No Comments2 Mins Read
NAS Devices
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 5, 2024Ravi LakshmananVulnerability / Data Security

NAS devices

Taiwanese network attached storage (NAS) manufacturer Synology has fixed a critical security flaw that affects DiskStation and BeePhotos and could lead to remote code execution.

Tracked as CVE-2024-10443 and duplicated RISK: STATION by Midnight Blue, the zero-day flaw was demonstrated at the Pwn2Own Ireland 2024 hacking competition by security researcher Rick de Jager.

RISK:STATION is “an unauthenticated zero-click vulnerability that allows attackers to gain root-level code execution on popular Synology DiskStation and BeeStation NAS devices, affecting millions of devices,” a Dutch company said.

The zero-click nature of the vulnerability means that it does not require any user interaction to trigger the exploit, allowing attackers to gain access to devices to steal sensitive data and install additional malware.

Cyber ​​security

The flaw affects the following versions −

No further technical details about the vulnerability have been released yet to give customers enough time to apply the fixes. Midnight Blue said there are between one and two million Synology devices that are currently both exposed and exposed to the Internet.

QNAP fixes 3 critical bugs

The disclosure comes after QNAP fixed three critical flaws affecting QuRouter, SMB Service and HBS 3 Hybrid Backup Sync, all of which were exploited during Pwn2Own –

  • CVE-2024-50389 – Fixed in QuRouter 2.4.5.032 and later
  • CVE-2024-50387 – Fixed in SMB Service 4.15.002 and SMB Service h4.15.002 and later
  • CVE-2024-50388 – Fixed in HBS 3 Hybrid Backup Sync 25.1.1.673 and later

​​​​​​While there is no evidence that any of the aforementioned vulnerabilities have been exploited in the wild, users are encouraged to apply the patches as soon as possible, given that NAS devices have been valuable targets for ransomware attacks in the past.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025

RCE Critical Error RCE Rate 9.9 CVSS in Backup and Replication

June 18, 2025

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

CISA warns about the active exploitation of vulnerability of the Linux kernel escalation

June 18, 2025

Ex-Analytics-Tsru, sentenced to 37 months for leaks of secret documents on national protection

June 18, 2025

Iran slows the Internet to prevent cyber -napades against the background of escalation of regional conflict

June 18, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.