Record summary

CVE-2024-29974 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC.

Description

** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE List< V5.21(AAZF.17)C0affected
Before v5.21\(aazf.17\)coaffected

Default status: unaffected, unknown

CVE List< V5.21(ABAG.14)C0affected
Before 5.21\(abag.14\)coaffected

Proofs of concept

1

Repository PoCs

GitHubPommaq/CVE-2024-29972-CVE-2024-29976-CVE-2024-29973-CVE-2024-29975-CVE-2024-29974-pocRepository PoCby PommaqStars: 4Not analyzed5 files

11.1 KiB · linked to 5 vulnerabilities

GitHub

PoC details

References

3