Skip to content

CVE-2025-12686

CVE

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 11, 2025
Last Seen
November 11, 2025
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical zero-day vulnerability in Synology's BeeStation OS allows remote code execution (RCE) on unpatched devices. The flaw, originating from a buffer overflow, has a CVSS score of 9.8, indicating severe risk. Synology has acknowledged the issue and is preparing updates to mitigate the threat.

A critical security vulnerability (CVE-2025-12686, CVSS 9.8) was discovered in Synology's BeeStation during Pwn2Own 2025 in Ireland. This vulnerability allows attackers to execute arbitrary code remotely due to a buffer copy issue without proper size checking. Synology has released updates to mitiga...

Public Exploits

Checking GitHub for proof-of-concept code…