CVE-2024-29972: OS Command Injection
UNSUPPORTED WHEN ASSIGNED The command injection vulnerability in the CGI program "remotehelp-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29972?
CVE-2024-29972 is classified as a critical command injection vulnerability that could allow unauthenticated attackers to execute operating system commands.
How do I fix CVE-2024-29972?
To fix CVE-2024-29972, update the Zyxel NAS326 firmware to version V5.21(AAZF.17)C0 or the NAS542 firmware to version V5.21(ABAG.14)C0.
Which products are affected by CVE-2024-29972?
The affected products for CVE-2024-29972 are Zyxel NAS326 and NAS542 running firmware versions prior to V5.21(AAZF.17)C0 and V5.21(ABAG.14)C0 respectively.
Is there a workaround for CVE-2024-29972?
Currently, there is no documented workaround for CVE-2024-29972 other than applying the necessary firmware updates.
What does CVE-2024-29972 allow an attacker to do?
CVE-2024-29972 potentially allows an unauthenticated attacker to execute arbitrary operating system commands on the vulnerable NAS devices.