** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 22 Jan 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyxel
Zyxel nas326 Zyxel nas326 Firmware Zyxel nas542 Zyxel nas542 Firmware |
|
| CPEs | cpe:2.3:h:zyxel:nas326:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:nas542:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Zyxel
Zyxel nas326 Zyxel nas326 Firmware Zyxel nas542 Zyxel nas542 Firmware |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2024-08-02T01:17:58.671Z
Reserved: 2024-03-22T08:49:44.342Z
Link: CVE-2024-29972
Updated: 2024-08-02T01:17:58.671Z
Status : Analyzed
Published: 2024-06-04T02:15:47.960
Modified: 2025-01-22T22:39:02.917
Link: CVE-2024-29972
No data.
OpenCVE Enrichment
No data.
Weaknesses