CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-29973

CVSS 9.8v3.1pub. 2024-06-04upd. 2025-01-22

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

🤖 AI Analysis
How it works

An attacker sends a crafted HTTP POST request containing a malicious payload in the "setCookie" parameter. The device firmware does not properly validate the transmitted data, resulting in its direct passage to the operating system command interpreter (CWE-78). The attack requires no authentication or user interaction and can be carried out remotely over the network.

Impact

An attacker can remotely execute arbitrary operating system commands on a vulnerable NAS device, which can consequently lead to complete takeover of the device, data leakage from stored information, or system integrity violation.

Mitigation & patch

Update Zyxel NAS326 firmware to version V5.21(AAZF.17)C0 or newer and Zyxel NAS542 to version V5.21(ABAG.14)C0 or newer according to manufacturer recommendations. Due to the unsupported status of these devices, it is recommended to consider replacing them with currently supported models and restricting access to the device management interface to trusted networks or IP addresses only.

Who is affected

Zyxel NAS326 with firmware versions earlier than V5.21(AAZF.17)C0 and Zyxel NAS542 with firmware versions earlier than V5.21(ABAG.14)C0. The manufacturer marked the products as unsupported at the time of CVE assignment (UNSUPPORTED WHEN ASSIGNED).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Zyxel Nas326

    HW
    Zyxel
    all versions
  • Zyxel Nas326 Firmware

    OS
    Zyxel
    < 5.21\(aazf.17\)c0
  • Zyxel Nas542

    HW
    Zyxel
    all versions
  • Zyxel Nas542 Firmware

    OS
    Zyxel
    < 5.21\(abag.14\)c0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2023-27992CRITICAL9.8⚠ KEVPL ✓same product

Zyxel NAS — pre-authentication command injection w firmware NAS326/540/542

CVE-2020-9054CRITICAL9.8⚠ KEVPL ✓same product

Pre-auth command injection w urządzeniach Zyxel NAS — RCE z uprawnieniami root

CVE-2024-6342CRITICAL9.8PL ✓same product

Command injection w Zyxel NAS326/NAS542 — zdalne wykonanie poleceń OS

CVE-2024-29974CRITICAL9.8PL ✓same product

RCE w Zyxel NAS326/NAS542 — nieuwierzytelnione wykonanie kodu przez upload pliku

CVE-2024-29972CRITICAL9.8PL ✓same product

Command injection w Zyxel NAS326/NAS542 — nieuwierzytelnione RCE