Junglewise Threat Intelligence

CVE-2025-12686: Synology BeeStation buffer overflow in AdminCenter

CVE-2025-12686 · Severity: critical · CVSS 9.8 · Published 2026-05-27

Vendors: Synology.

Executive brief

Synology BeeStation is a personal cloud storage device used by individuals and small businesses to manage and back up data. A critical security flaw in the device's management interface allows an unauthorized person to remotely take control of the system over the network. This could lead to the theft of private files, total loss of data, or the device being used as a foothold for further attacks on the local network.

Technical details

A classic buffer overflow (CWE-120) exists in the AdminCenter component of Synology BeeStation Manager (BSM) and BeeStation OS. The vulnerability is caused by a buffer copy operation that does not validate the size of the input, leading to memory corruption. A remote, unauthenticated attacker can exploit this flaw over the network without any user interaction. Successful exploitation allows for arbitrary code execution with high privileges on the underlying operating system. This vulnerability was identified during the Pwn2Own 2025 competition and is resolved in version 1.3.2-65648 and later.

Affected products

  • Synology BeeStation Manager (BSM) before 1.3.2-65648
  • Synology BeeStation OS before 1.3.2-65648

Timeline

  • 2025-11-10: advisory: Initial public release by Synology
  • 2025-11-10: patched: Fixed in version 1.3.2-65648
  • 2026-05-27: disclosed: NVD publication date

References