CVE-2024-10441

Published Mar 19, 2025

Last updated 4 months ago

Overview

Description
Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.
Source
security@synology.com
NVD status
Analyzed
Products
beestation_os, diskstation_manager

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@synology.com
CWE-116

Social media

Hype score
Not currently trending
  1. 🚨 TrustWallet Hacker Infrastructure Discovered A hacked Synology NAS running DSM 6.2.4 is likely vulnerable to RCE (CVE-2024-10441) IOCs: metrics-trustwallet[.]com 138.124.70[.]40 141.224.241[.]45 At https://t.co/MUdaGoASoS, we track when Web2 is weaponized in Web3 attacks

    @chainaraio

    26 Dec 2025

    5310 Impressions

    2 Retweets

    7 Likes

    0 Bookmarks

    2 Replies

    1 Quote

  2. Vulnerabilidad crítica de Synology permite a atacantes ejecutar código arbitrario de forma remota Synology’s DiskStation Manager (DSM) CVE-2024-10441 https://t.co/b5gMuifh3w… https://t.co/bBFgSKh8vf

    @doncaptador

    22 Mar 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Vulnerabilidad crítica de Synology permite a atacantes ejecutar código arbitrario de forma remota Synology’s DiskStation Manager (DSM) CVE-2024-10441 https://t.co/ViBiT4wIOy https://t.co/cOjBKmYeTx

    @elhackernet

    21 Mar 2025

    6000 Impressions

    24 Retweets

    80 Likes

    17 Bookmarks

    0 Replies

    1 Quote

  4. Warning: Attackers can exploit critical vulnerability CVE-2024-10441 (CVSS 9.8) in various versions of #Synology BeeStation Manager (BSM), DiskStation Manager (DSM), and Unified Controller (DSMUC) to execute remote code. Advisory available at:https://t.co/rGH7G44zhX #Patch #Patch

    @CCBalert

    19 Mar 2025

    109 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-10441 (CVSS 9.8): Synology Patches Critical Code Execution Flaw A severe remote code execution vulnerability in multiple Synology products has been patched to prevent exploitation. https://t.co/aoSpqQFNZ3 #Cybersecurity #RCE #SynologySecurity

    @adriananglin

    19 Mar 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-10441 Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation Manager (BSM) before 1.1-65374, Synology DiskStation Manager … https://t.co/VKENG8plrb

    @CVEnew

    19 Mar 2025

    503 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2024-10441: CRITICAL] Vulnerabilities in Synology DSM & BSM can expose systems to remote code execution via unescaped output. Update to DSM 6.2.4-25556-8 or later to mitigate risks.#cybersecurity,#vulnerability https://t.co/owu5TcLyKb https://t.co/d6unXLv6rF

    @CveFindCom

    19 Mar 2025

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations