Zyxel NAS542和Zyxel NAS326都是中国合勤(Zyxel)公司的产品。Zyxel NAS542是一款NAS(网络附加存储)设备。Zyxel NAS326是一款云存储 NAS。 Zyxel NAS326 V5.21(AAZF.17)C0之前版本、NAS542 V5.21(ABAG.14)C0之前版本存在操作系统命令注入漏洞,该漏洞源于setCookie参数中存在命令注入漏洞,从而导致攻击者可通过HTTP POST请求来执行某些操作系统 (OS) 命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zyxel | NAS326 firmware | < V5.21(AAZF.17)C0 | - |
|
| Zyxel | NAS542 firmware | < V5.21(ABAG.14)C0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/momika233/CVE-2024-29973 | POC Details |
| 2 | POC for CVE-2024-29973 | https://github.com/bigb0x/CVE-2024-29973 | POC Details |
| 3 | None | https://github.com/k3lpi3b4nsh33/CVE-2024-29973 | POC Details |
| 4 | PoC and Bulk Scanner for CVE-2024-29973 | https://github.com/p0et08/CVE-2024-29973 | POC Details |
| 5 | Exploiter a Vulnerability detection and Exploitation tool for CVE-2024-29973 with Asychronous Performance. | https://github.com/RevoltSecurities/CVE-2024-29973 | POC Details |
| 6 | None | https://github.com/skyrowalker/CVE-2024-29973 | POC Details |
| 7 | None | https://github.com/0xlf/CVE-2024-29973 | POC Details |
| 8 | The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29973.yaml | POC Details |
| 9 | None | https://github.com/NanoWraith/CVE-2024-29973 | POC Details |
| 10 | None | https://github.com/zxcod3/CVE-2024-29973 | POC Details |
| 11 | None | https://github.com/0zerobyte/CVE-2024-29973 | POC Details |
| 12 | None | https://github.com/voidbroker/CVE-2024-29973 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-29974 | 9.8 CRITICAL | Zyxel NAS326和Zyxel NAS542 代码问题漏洞 |
| CVE-2024-29972 | 9.8 CRITICAL | Zyxel NAS326和Zyxel NAS542 操作系统命令注入漏洞 |
| CVE-2024-29975 | 6.7 MEDIUM | Zyxel NAS326和Zyxel NAS542 安全漏洞 |
| CVE-2024-29976 | 6.5 MEDIUM | Zyxel NAS326和Zyxel NAS542 安全漏洞 |
No comments yet