← Back

CVE-2024-29973

Published: Jun 4, 2024Modified: Jan 22, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: security@zyxel.com.tw (Secondary)

Description

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

Affected (2)

2 products
Nas326 Firmware
Nas542 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.21\(aazf.17\)c0
Running on/withPlatform Versions
Zyxel
Nas326
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.21\(abag.14\)c0
Running on/withPlatform Versions
Zyxel
Nas542
All versions

Timeline

No history available yet.