### [CVE-2024-10441](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10441) ![](https://img.shields.io/static/v1?label=Product&message=BeeStation%20OS%20(BSM)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=DiskStation%20Manager%20(DSM)&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=1.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=1.1%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=7.1%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=7.2%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=7.2.1%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=7.2.2%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Encoding%20or%20Escaping%20of%20Output&color=brightgreen) ### Description Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/hazzzein/CVE-2024-10441 - https://github.com/nomi-sec/PoC-in-GitHub - https://github.com/plzheheplztrying/cve_monitor