Record summary

CVE-2024-29972 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs and 1 Nuclei template.

Description

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
2
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE List, VulnCheck< V5.21(AAZF.17)C0affected
Before v5.21\(aazf.17\)coaffected

Default status: unaffected, unknown

CVE List< V5.21(ABAG.14)C0affected
Before 5.21\(abag.14\)coaffected

Proofs of concept

2

Repository PoCs

GitHubWanLiChangChengWanLiChang/CVE-2024-29972Repository PoCby WanLiChangChengWanLiChangStars: 1Not analyzed2 files

2.9 KiB

GitHub

PoC details
GitHubPommaq/CVE-2024-29972-CVE-2024-29976-CVE-2024-29973-CVE-2024-29975-CVE-2024-29974-pocRepository PoCby PommaqStars: 4Not analyzed5 files

11.1 KiB · linked to 5 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALZyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor AccountCVSS 9.88

The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

Impact

Attackers can use the backdoor account to gain unauthorized administrative access to the NAS device.

Remediation

Update Zyxel NAS326 firmware to a version that removes the backdoor account.

WeaknessesCWE-78
Authorsgy741
Template tagscvecve2024zyxelbackdoorvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*
FOFA: app="ZYXEL-NAS326"

Source: ProjectDiscovery

References

3