{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T10:04:22.521","vulnerabilities":[{"cve":{"id":"CVE-2024-29973","sourceIdentifier":"security@zyxel.com.tw","published":"2024-06-04T02:15:48.290","lastModified":"2026-06-17T07:23:28.277","vulnStatus":"Analyzed","cveTags":[{"sourceIdentifier":"security@zyxel.com.tw","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED **\nThe command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request."},{"lang":"es","value":"** NO SOPORTADO CUANDO S ASIGNÓ ** La vulnerabilidad de inyección de comando en el parámetro “setCookie” en las versiones de firmware Zyxel NAS326 anteriores a V5.21(AAZF.17)C0 y en las versiones de firmware NAS542 anteriores a V5.21(ABAG.14)C0 podría permitir una atacante ejecutar algunos comandos del sistema operativo (SO) enviando una solicitud HTTP POST manipulada."}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"NAS326 firmware","defaultStatus":"unaffected","versions":[{"version":"< V5.21(AAZF.17)C0","status":"affected"}]},{"vendor":"Zyxel","product":"NAS542 firmware","defaultStatus":"unaffected","versions":[{"version":"< V5.21(ABAG.14)C0","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"zyxel","product":"nas326_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:nas326_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"v5.21\\(aazf.17\\)co","versionType":"custom","status":"affected"}]},{"vendor":"zyxel","product":"nas542_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:zyxel:nas542_firmware:-:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"5.21\\(abag.14\\)co","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-04T00:00:00+00:00","id":"CVE-2024-29973","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.21\\(aazf.17\\)c0","matchCriteriaId":"DF437A28-8199-4AB6-9F07-F061994C0D9C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nas326:-:*:*:*:*:*:*:*","matchCriteriaId":"E0A01B19-4A91-4FBC-8447-2E854346DAC5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.21\\(abag.14\\)c0","matchCriteriaId":"718ACAC1-C0E1-45DF-A23E-7A7F9CCF1373"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nas542:-:*:*:*:*:*:*:*","matchCriteriaId":"31C4DD0F-28D0-4BF7-897B-5EEC32AA7277"}]}]}],"references":[{"url":"https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/","source":"security@zyxel.com.tw","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024","source":"security@zyxel.com.tw","tags":["Vendor Advisory"]},{"url":"https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}