CVE-2024-50629PoC(synology / beestation_os)

HIGHCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for synology beestation_os systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • beestation_os
  • diskstation_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
beestation_osdiskstation_manager

4 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-06: 2Mentions · 2026-04-13: 1Mentions · 2026-05-30: 1PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-05-30: 1Exploit Tool / Code · 2026-03-06: 1Exploit Tool / Code · 2026-05-30: 1Active Exploitation · 2026-03-06: 1Technical Details · 2026-03-06: 2Technical Details · 2026-05-30: 103-0604-1305-30
Signal classification3 categories
PoC
250.0%
Exploit
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-062
Exploit1General1
2026-04-131
PoC1
2026-05-301
PoC1
Full discourse4 posts
  • 0xor0ne@0xor0ne
    Exploit

    Exploiting the Synology BeeStation (BST150-4T), CRLF injection, auth bypass, and SQLite injection to RCE (CVE-2024-50629~50631) https://kiddo-pwn.github.io/blog/2025-11-30/writing-sync-popping-cron Credits @kiddo_pwn @infosec https://t.co/Z415KhbcLy

    Post summary

    The tweet announces a blog detailing exploitation of Synology BeeStation devices (BST150‑4T) via CRLF injection, authentication bypass, and SQLite injection to achieve remote code execution for CVE‑2024‑50629 to 50631, providing a PoC and exploit methodology.

    1380160788.0K
    88.4K followersView on X
  • 0xor0ne@0xor0ne
    PoC

    Exploiting the Synology BeeStation (BST150-4T) by @kiddo_pwn (CVE-2024-50629~50631) https://kiddo-pwn.github.io/blog/2025-11-30/writing-sync-popping-cron @infosec https://t.co/QOQfe5Hsvv

    Post summary

    A proof‑of‑concept for the Synology BeeStation vulnerabilities (CVE‑2024‑50629 to 50631) is shared via a linked blog post, with no active exploitation, mitigation, or technical detail in the tweet itself.

    013084365.1K
    91.4K followersView on X
  • eleven red pandas@bytecodevm
    PoC

    A deep technical write-up of the Synology BeeStation pre-auth-to-RCE chain disclosed by DEVCORE at Pwn2Own Ireland 2024 (CVE-2024-50629 CRLF injection, CVE-2024-50630 auth bypass via webapi-to-syncd domain-socket trust, CVE-2024-50631 SQL injection in update_settings) plus an N-day variant by Kiddo that swaps DEVCORE’s PHP-based RCE for a novel "ATTACH DATABASE" primitive against "/etc/cron.d/pwn.task", exploiting cron’s line-skip tolerance to embed a working reverse-shell crontab inside an otherwise-binary SQLite file. https://core-jmp.org/2026/05/kiddo-pwn-synology-beestation-sqlite-cron-rce-cve-2024-50629-50631/ #ATTACHDATABASE #AuthenticationBypass #BeeStation #CommandInjection #CRLFInjection #CronAbuse #CVE #CVE202450629 #CVE202450630 #CVE202450631 #NdayResearch #Pwn2Own #RCE #SQLInjection #SQLite #Synology #SynologyDriveServer #UnauthenticatedRCE #VulnerabilityResearch #XAccelRedirect

    Post summary

    The tweet announces a detailed technical write‑up of a pre‑auth RCE chain in Synology BeeStation (CVE‑2024‑50629‑50631), shares a PoC link and elaborates on the exploit technique, but does not mention active attacks, patches or false‑positive claims.

    00031130
    1.9K followersView on X
  • VulnTracker@vuln_tracker
    General

    @0xor0ne @kiddo_pwn @infosec Thanks for sharing! Excellent collaboration on CVE-2024-50629~50631! Multi-stage Synology BeeStation exploitation showing CRLF to RCE progression. This is why we need detailed technical research. Track and monitor this CVE: http://Vulntracker.io

    Post summary

    The tweet acknowledges the CVE and notes a progression from CRLF to RCE but provides no concrete PoC, exploit code, or patch information. It serves as a broad mention rather than detailed disclosure.

    00011228
    392 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSsynologybeestation_os1.0--
OSsynologybeestation_os1.0--
OSsynologybeestation_os1.0--
OSsynologybeestation_os1.0--
OSsynologybeestation_os1.0.1--
OSsynologybeestation_os1.0.2--
OSsynologybeestation_os1.0.2--
OSsynologybeestation_os1.1--
OSsynologybeestation_os1.1--
OSsynologydiskstation_manager---

Explore more