CVE-2024-29972 is a critical command injection vulnerability in the "remote_help-cgi" program of Zyxel NAS326 (firmware before V5.21(AAZF.17)C0) and NAS542 (firmware before V5.21(ABAG.14)C0) devices. It allows an unauthenticated attacker to execute arbitrary operating system commands by sending a crafted HTTP POST request. With a CVSS score of 9.8 (Critical), this vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Although not yet listed in CISA's KEV catalog, its high EPSS score (0.9268) and FAUCET Risk Score (100/100) indicate a high likelihood of exploitation, further supported by community discussion, media coverage, and the existence of Nuclei templates for a related backdoor account.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.21\(aazf.17\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:* | ||
< 5.21\(abag.14\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.