CVE-2024-11131

A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.2.0-0525 may be affected: BC500, CC400W and TC500.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:synology:bc500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:bc500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:synology:cc400w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:cc400w:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:synology:tc500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:tc500:-:*:*:*:*:*:*:*

History

16 Jan 2026, 15:40

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad relacionada con la lectura fuera de los límites en la interfaz de vídeo. Esto permite a atacantes remotos ejecutar código arbitrario mediante vectores no especificados. Los siguientes modelos con versiones de Synology Camera Firmware anteriores a la 1.2.0-0525 podrían verse afectados: BC500, CC400W y TC500.
References () https://www.synology.com/en-global/security/advisory/Synology_SA_24_24 - () https://www.synology.com/en-global/security/advisory/Synology_SA_24_24 - Vendor Advisory
CPE cpe:2.3:o:synology:cc400w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:tc500:-:*:*:*:*:*:*:*
cpe:2.3:h:synology:cc400w:-:*:*:*:*:*:*:*
cpe:2.3:o:synology:bc500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:tc500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:bc500:-:*:*:*:*:*:*:*
First Time Synology tc500
Synology cc400w Firmware
Synology
Synology bc500 Firmware
Synology bc500
Synology cc400w
Synology tc500 Firmware

19 Mar 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-19 03:15

Updated : 2026-01-16 15:40


NVD link : CVE-2024-11131

Mitre link : CVE-2024-11131

CVE.ORG link : CVE-2024-11131


JSON object : View

Products Affected

synology

  • bc500
  • tc500
  • cc400w
  • tc500_firmware
  • bc500_firmware
  • cc400w_firmware
CWE
CWE-125

Out-of-bounds Read