CVE-2024-11131
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
19/03/2025
Last modified:
16/01/2026
Description
A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:synology:bc500_firmware:*:*:*:*:*:*:*:* | 1.2.0-0525 (excluding) | |
| cpe:2.3:h:synology:bc500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synology:cc400w_firmware:*:*:*:*:*:*:*:* | 1.2.0-0525 (excluding) | |
| cpe:2.3:h:synology:cc400w:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:synology:tc500_firmware:*:*:*:*:*:*:*:* | 1.2.0-0525 (excluding) | |
| cpe:2.3:h:synology:tc500:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



