← Back

CVE-2024-29975

nvd nist
Published: Jun 4, 2024Modified: Jan 22, 2025

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: security@zyxel.com.tw (Secondary)

Description

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a vulnerable device.

Affected (2)

2 products
Nas326 Firmware
Nas542 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.21\(aazf.17\)c0
Running on/withPlatform Versions
Zyxel
Nas326
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 5.21\(abag.14\)c0
Running on/withPlatform Versions
Zyxel
Nas542
All versions

Timeline

No history available yet.