Synology BeeStation Vulnerabilities & Security Advisories
2 advisories tracked · Synology PSIRT (security@synology.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Synology advisory that VulniPulse classified as BeeStation, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 1 high.
Android app · Google Play
Monitor Synology CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Synology PSIRT (security@synology.com CNA) via NVD
Synology is its own CVE Numbering Authority. VulniPulse ingests Synology's CVEs from the NVD CNA feed (security@synology.com), grouped by their official Synology_SA_YY_NN advisory, then enriches each from the advisory page — a fully server-rendered page carrying Synology's own severity rating, the affected-product / fixed-release table and the mitigation section. Covers DSM (DiskStation Manager), SRM (Router Manager), BeeStation, Synology Photos, Surveillance Station, Synology Drive and the SSL VPN Client.
Latest Synology BeeStation advisories
Critical [CVE-2025-12686] BeeStation OS 1.3: Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS…
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors. Affected products named by the advisory: BeeStation OS 1.3; BeeStation OS 1.2; BeeStation OS 1.1; BeeStation OS 1.0.
High [CVE-2023-52945 +1] Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.