nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-29974 CVE-2024-29974
CRITICAL
Record summary
CVE-2024-29974 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC.
Description
** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
NAS326 firmwareBrowse Zyxel / NAS326 firmwareDefault status: unaffected, unknown | CVE List | < V5.21(AAZF.17)C0 | affected |
| Before v5.21\(aazf.17\)co | affected | ||
NAS542 firmwareBrowse Zyxel / NAS542 firmwareDefault status: unaffected, unknown | CVE List | < V5.21(ABAG.14)C0 | affected |
| Before 5.21\(abag.14\)co | affected |
Proofs of concept
1Repository PoCs
GitHubPommaq/CVE-2024-29972-CVE-2024-29976-CVE-2024-29973-CVE-2024-29975-CVE-2024-29974-pocRepository PoCby PommaqStars: 4Not analyzed5 files
References
3outpost24.com
https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities zyxel.comVendor advisory
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024