CVE-2024-6342: OS Command Injection
UNSUPPORTED WHEN ASSIGNED A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6342?
CVE-2024-6342 is classified as a command injection vulnerability, which is considered a critical severity due to its potential to allow unauthenticated attackers to execute OS commands.
How do I fix CVE-2024-6342?
To mitigate CVE-2024-6342, users should update the firmware of their Zyxel NAS326 or NAS542 devices to the latest version provided by Zyxel.
Which software versions are affected by CVE-2024-6342?
CVE-2024-6342 affects Zyxel NAS326 firmware versions up to V5.21(AAZF.18)C0 and Zyxel NAS542 firmware versions up to V5.21(ABAG.15)C0.
Can CVE-2024-6342 be exploited remotely?
Yes, CVE-2024-6342 can be exploited by unauthenticated attackers remotely, making it a serious threat.
What devices are impacted by CVE-2024-6342?
CVE-2024-6342 impacts the Zyxel NAS326 and NAS542 network-attached storage devices.