CVE-2025-12686: Synology Beestation OS
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected products
- Synology Beestation OS: from 1.0, before 1.3.2 (fixed in 1.3.2)
Published 2026-05-27. Last modified 2026-10-07.