CVE-2024-29973: OS Command Injection
UNSUPPORTED WHEN ASSIGNED The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29973?
CVE-2024-29973 is a command injection vulnerability that can lead to remote code execution on affected devices.
How do I fix CVE-2024-29973?
To fix CVE-2024-29973, upgrade Zyxel NAS326 firmware to V5.21(AAZF.17)C0 or NAS542 firmware to V5.21(ABAG.14)C0.
Which devices are affected by CVE-2024-29973?
The affected devices for CVE-2024-29973 are Zyxel NAS326 and Zyxel NAS542 running firmware versions prior to the specified fixed versions.
Can CVE-2024-29973 be exploited remotely?
Yes, an unauthenticated attacker can exploit CVE-2024-29973 remotely through the vulnerable 'setCookie' parameter.
Is there a workaround for CVE-2024-29973?
There are no known workarounds for CVE-2024-29973; updating the firmware is the recommended solution.