CVE-2025-12686 is a vulnerability tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 11, 2025; most recent activity November 11, 2025.
A critical zero-day vulnerability in Synology's BeeStation OS allows remote code execution (RCE) on unpatched devices. The flaw, originating from a buffer overflow, has a CVSS score of 9.8, indicating severe risk.…
A critical security vulnerability (CVE-2025-12686, CVSS 9.8) was discovered in Synology's BeeStation during Pwn2Own 2025 in Ireland. This vulnerability allows attackers to execute arbitrary code remotely due to a buffer…