Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29973


** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.


Published

2024-06-04T02:15:48.290

Last Modified

2025-01-22T22:40:25.990

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel nas326_firmware < 5.21\(aazf.17\)c0 Yes
Hardware zyxel nas326 - No
Operating System zyxel nas542_firmware < 5.21\(abag.14\)c0 Yes
Hardware zyxel nas542 - No

References