Hackers Exploited 34 Zero-Day Vulnerabilities And Earned $522,500 In Pwn2Own Ireland 2025
On the first day of Pwn2Own Ireland 2025, security researchers identified 34 unique zero-day vulnerabilities in various smart devices. The event took place in Cork, Ireland, from October 21 to 24, and participants received a total of $522,500 in prizes.…
On the first day of Pwn2Own Ireland 2025, security researchers identified 34 unique zero-day vulnerabilities in various smart devices. The event took place in Cork, Ireland, from October 21 to 24, and participants received a total of $522,500 in prizes. The event challenges hackers to test the security of popular gadgets, including printers, routers, and smart home systems.
Key Outcomes and Technical Achievements
The team "DDOS" successfully exploited the QNAP Qhora-322 router and TS-453E NAS device using eight different vulnerabilities, including injection bugs, earning $100,000 and 10 points in the competition. Team Neodyme achieved a stack buffer overflow on the HP DeskJet 2855e printer, receiving $20,000. Synacktiv executed root-level code on the Synology BeeStation Plus via a stack overflow, securing $40,000. STAR Labs used a heap buffer overflow on the Canon imageCLASS MF654Cdw printer to win $20,000. SHIMIZU Yutaro from GMO Cybersecurity earned $10,000 through a stack overflow on the same Canon model. Team PetoWorks exploited an invalid pointer release bug, earning an additional $10,000. Team ANHTUD utilized a heap buffer overflow, securing $10,000. Sina Kheirkhah from Summoning Team used two vulnerabilities for code execution on the Synology DiskStation DS925+, receiving $40,000. Stephen Fewer from Rapid7 combined multiple flaws to breach the Home Assistant Green hub, earning $40,000. Compass Security employed an arbitrary file write and data leak on the same device for $20,000. dmdung from STAR Labs achieved an out-of-bounds access on the Sonos Era 300 speaker, claiming $50,000. Team ANHTUD's four-bug chain on the Philips Hue Bridge, including overflows, earned them $40,000. Hank Chen from InnoEdge Labs implemented an authentication bypass and out-of-bounds write for $20,000. DEVCORE Research Team found multiple injections and a format string bug on the QNAP TS-453E, securing $40,000. Summoning Team ended with two exploits on the Synology ActiveProtect DP320 appliance for $50,000. McCaulay Hudson from Summoning employed four bugs on Home Assistant Green, earning $12,500.
Seventeen attempts were made during the day, focusing on network storage, printers, and surveillance gear. Summoning Team leads the standings with 11.5 points, followed by Team DDOS with 10 points. Points contribute to the competition’s conclusion to determine the top hacker title.
On the first day of Pwn2Own Ireland 2025, security researchers identified 34 unique zero-day vulnerabilities in various smart devices.
The Pwn2Own Ireland event allows vendors 90 days to patch disclosed vulnerabilities. It offers up to $2 million in prizes, including $1 million for a zero-click WhatsApp exploit. Day two will focus on network storage, printers, smart homes, and the Samsung Galaxy S25 smartphone. The event is anticipated to surpass last year’s awards, with new targets including wearables from Meta.
For live updates, follow the Zero Day Initiative on social media. These findings aim to enhance security for users of connected devices.
Based on reporting by Cyber Security News.
