Synology-SA-25:12 BeeStation (PWN2OWN 2025)

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Critical
Status
Resolved

Abstract

Synology has released a security update for the BeeStation OS to address ZDI-CAN-28275 :
      • CVE-2025-12686 allows remote attackers to execute arbitrary code.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
BeeStation OS 1.3 Critical Upgrade to 1.3.2-65648 or above.
BeeStation OS 1.2 Critical Upgrade to 1.3.2-65648 or above.
BeeStation OS 1.1 Critical Upgrade to 1.3.2-65648 or above.
BeeStation OS 1.0 Critical Upgrade to 1.3.2-65648 or above.

Mitigation

None

Detail

Acknowledgement

@Tek_7987 & @_Anyfun (@Synacktiv)

Reference

CVE-2025-12686

Revision

Revision Date Description
1 2025-11-10 Initial public release.