Synology is telling NAS device users to release a patch immediately after the zero-day reveal


  • Synology has fixed a zero-click error found in multiple NAS products
  • This type of flaw can be exploited without victim intervention, making it particularly dangerous
  • Technical details have not been disclosed to give customers time to respond

Top Network-Attached Storage (NAS) manufacturers Synology has patched a critical vulnerability that could allow threat actors to remotely execute malicious code on affected endpoints.

The vulnerability is tracked as CVE-2024-10443 and was found in DiskStation and BeePhotos. It was demonstrated at the recent Pwn2Own Ireland 2024 hackathon, where it was described as a zero-click bug and named RISK:STATION.