A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500.
2024-06-28T07:15:06.330
2025-03-06T14:28:45.740
Analyzed
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | synology | bc500_firmware | < 1.0.7-0298 | Yes |
| Hardware | synology | bc500 | - | No |
| Operating System | synology | tc500_firmware | < 1.0.7-0298 | Yes |
| Hardware | synology | tc500 | - | No |