CVE-2024-29973
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 86%
from disclosure to weapon15 days
Published on NVDJun 4
1st PoC+15d
VulnCheck+20d
exploitation probability
86%top 1% of all CVEs
observed exploitation
yesVulnCheck
14 public exploit(s)
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
public PoCs found — 14
githubgithub.com/bigb0x/CVE-2024-29973★ 10githubgithub.com/NanoWraith/CVE-2024-29973★ 10githubgithub.com/RevoltSecurities/CVE-2024-29973★ 6githubgithub.com/momika233/CVE-2024-29973★ 3githubgithub.com/intel365/CVE-2024-29973★ 2githubgithub.com/p0et08/CVE-2024-29973★ 0vulncheckvulncheck.com/xdb/e9f896d58c7bunverifiedvulncheckvulncheck.com/xdb/372a4b801c8cunverifiedvulncheckvulncheck.com/xdb/5244506c48cfunverifiedvulncheckvulncheck.com/xdb/f6609fb90315unverifiedvulncheckvulncheck.com/xdb/d9b1def057bbunverifiedvulncheckvulncheck.com/xdb/80b55759e2dfunverifiedvulncheckvulncheck.com/xdb/4e87a1cc9d12unverifiedvulncheckvulncheck.com/xdb/34525b555a68unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.