CVE-2024-10443: Synology Beephotos
Critical severity, CVSS 9.8. EPSS: 28% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected products
- Synology Beephotos: before 1.1.0-10053 (fixed in 1.1.0-10053); before 1.0.2-10026 (fixed in 1.0.2-10026)
- Synology Photos: before 1.6.2-0720 (fixed in 1.6.2-0720); before 1.7.0-0795 (fixed in 1.7.0-0795)
Published 2024-11-15. Last modified 2026-06-17.