CVE-2024-29973 is a critical command injection vulnerability in Zyxel NAS326 and NAS542 firmware that allows an unauthenticated attacker to execute OS commands by sending a crafted HTTP POST request to the "setCookie" parameter. With a CVSS score of 9.8 (CRITICAL), it presents a severe threat due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, exploit intelligence indicates Nuclei templates exist, and community discussion and media coverage suggest active exploitation by botnets, even on end-of-life devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.21\(aazf.17\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:* | ||
< 5.21\(abag.14\)c0CPE matchmatch criteria | cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.