CVE-2024-29972
Zyxel nas326_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2024-29972 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs and 1 Nuclei template.
Description
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
NAS326 firmwareBrowse Zyxel / NAS326 firmwareDefault status: unaffected, unknown | CVE List, VulnCheck | < V5.21(AAZF.17)C0 | affected |
| Before v5.21\(aazf.17\)co | affected | ||
NAS542 firmwareBrowse Zyxel / NAS542 firmwareDefault status: unaffected, unknown | CVE List | < V5.21(ABAG.14)C0 | affected |
| Before 5.21\(abag.14\)co | affected |
Proofs of concept
2Repository PoCs
GitHubWanLiChangChengWanLiChang/CVE-2024-29972Repository PoCby WanLiChangChengWanLiChangStars: 1Not analyzed2 files
GitHubPommaq/CVE-2024-29972-CVE-2024-29976-CVE-2024-29973-CVE-2024-29975-CVE-2024-29974-pocRepository PoCby PommaqStars: 4Not analyzed5 files
Nuclei templates
1ProjectDiscoveryCRITICALZyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor AccountCVSS 9.88
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Impact
Attackers can use the backdoor account to gain unauthorized administrative access to the NAS device.
Remediation
Update Zyxel NAS326 firmware to a version that removes the backdoor account.
Source: ProjectDiscovery