S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 3, 2024

CVE-2024-29972 Scanner

CVE-2024-29972 scanner - Remote Code Execution (RCE) vulnerability in Zyxel NAS326 Firmware

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
NAS326 firmwareby Zyxel
< V5.21(AAZF.17)C0
NAS542 firmwareby Zyxel
< V5.21(ABAG.14)C0
nas326_firmwareby zyxel
AFFECTED< v5.21\(aazf.17\)co→SAFE ✓≥ v5.21\(aazf.17\)co
nas542_firmwareby zyxel
AFFECTED< 5.21\(abag.14\)co→SAFE ✓≥ 5.21\(abag.14\)co
Updated Sep 28, 2026View on NVD →
Detail

Zyxel NAS326 is a network-attached storage (NAS) device primarily used by small businesses and individuals to manage and store data efficiently. It provides centralized storage and is accessible over the internet, making it a convenient solution for data sharing and backup. The device is equipped with various security features to protect sensitive data. However, like many IoT devices, it can be vulnerable to specific cyber threats if not properly updated. Maintaining the latest firmware is critical to ensure the device remains secure.

The vulnerability in Zyxel NAS326 Firmware allows unauthenticated attackers to execute arbitrary OS commands remotely. This is due to improper input validation in the remote_help-cgi script. If exploited, the vulnerability can lead to full system compromise. It's essential to address this issue immediately by updating to the latest firmware version.

The vulnerability is located in the CGI program "remote_help-cgi" used in Zyxel NAS326 firmware. By sending a specially crafted HTTP POST request to this endpoint, an attacker can exploit improper input validation to inject OS commands. The "remote_help-cgi" script fails to properly sanitize the input, allowing command injection that could lead to remote code execution. This security flaw is critical because it does not require authentication, meaning any external attacker could exploit it.

If this vulnerability is exploited, an attacker could gain complete control over the Zyxel NAS326 device. They could execute arbitrary commands, potentially leading to unauthorized data access, deletion, or further network compromise. The attack could also be used to deploy malware or create backdoors for future access, posing a significant security risk to all data stored on the device.

By using the S4E platform, you gain access to robust tools for identifying and mitigating vulnerabilities like the one affecting Zyxel NAS326. Our platform helps you stay ahead of threats with timely vulnerability detection and actionable remediation steps. Protect your digital assets and ensure the security of your network with our comprehensive Cyber Threat Exposure Management services. Join now to take advantage of our expert-driven security solutions.

References:

Solution Advice
  • Update the Zyxel NAS326 firmware to version V5.21(AAZF.17)C0 or higher.
  • Regularly check for and apply firmware updates provided by Zyxel.
  • Restrict network access to the device and limit exposure to the internet.
  • Consider using additional security measures such as firewalls or VPNs to protect the device from unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.