CVE-2024-29972
published 2024-06-04CVE-2024-29972: ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
89.22%
99.8th percentile
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | nas326_firmware | < V5.21(AAZF.17)C0 | V5.21(AAZF.17)C0 |
| zyxel | nas326_firmware | < 5.21\(aazf.17\)c0 | 5.21\(aazf.17\)c0 |
| zyxel | nas542_firmware | < V5.21(ABAG.14)C0 | V5.21(ABAG.14)C0 |
| zyxel | nas542_firmware | < 5.21\(abag.14\)c0 | 5.21\(abag.14\)c0 |
Detection & IOCsextracted from sources · hover to see the quote
url/desktop,/cgi-bin/remote_help-cgi/favicon.ico?type=sshd_tdc
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel NAS CGI Command Injection (CVE-2024-29972)"; flow:established, to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/remote_help-cgi/"; content:"type=sshd_tdc"; fast_pattern; distance:0; reference:url,outpost24.com/blog/zyxel-nas-critical-vulnerabilities/; reference:cve,2024-29972; classtype:web-application-activity; sid:2055907; rev:1; metadata:affected_product Zyxel, tls_state plaintext, created_at 2024_09_18, cve CVE_2024_29972, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2024_09_18, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
- →Detect exploitation attempts by matching HTTP GET requests to the URI path '/cgi-bin/remote_help-cgi/' containing the query parameter 'type=sshd_tdc'.
- →A successful exploitation response will return HTTP 200 with the body containing 'result=0'.
- →The attack vector is an unauthenticated HTTP POST (or GET with crafted URI) request to the 'remote_help-cgi' CGI program; no authentication is required, making it detectable at the perimeter on plaintext HTTP traffic. ↗
- →FOFA fingerprint query 'app="ZYXEL-NAS326"' can be used to identify exposed Zyxel NAS326 devices on the internet for proactive asset identification.
- ·Both NAS326 and NAS542 are end-of-life products (support ended December 31, 2023); Zyxel issued emergency patches only for the three critical CVEs (CVE-2024-29972, -29973, -29974). Two other flaws (CVE-2024-29975, CVE-2024-29976) were NOT patched. ↗
- ·Public proof-of-concept (PoC) exploits are available, significantly raising the risk of in-the-wild exploitation even though Zyxel had not observed exploitation at time of disclosure. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9c67-m3v4-35rv: ** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5
ghsa_unreviewed·2024-06-04
CVE-2024-29972 [CRITICAL] CWE-78 GHSA-9c67-m3v4-35rv: ** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
VulnCheck
Zyxel nas326_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2024·CVSS 9.8
CVE-2024-29972 [CRITICAL] Zyxel nas326_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Zyxel nas326_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Affected: Zyxel nas326_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://app.crowdsec.net/cti/cve-explorer/CVE-2024-29972
Exploit PoC: https://vulncheck.com/xdb/891f1dbf629c; https://vulnchec
Suricata
ET WEB_SPECIFIC_APPS Zyxel NAS CGI Command Injection (CVE-2024-29972)
suricata·2024-09-18·CVSS 9.8
CVE-2024-29972 [CRITICAL] ET WEB_SPECIFIC_APPS Zyxel NAS CGI Command Injection (CVE-2024-29972)
ET WEB_SPECIFIC_APPS Zyxel NAS CGI Command Injection (CVE-2024-29972)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel NAS CGI Command Injection (CVE-2024-29972)"; flow:established, to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/remote_help-cgi/"; content:"type=sshd_tdc"; fast_pattern; distance:0; reference:url,outpost24.com/blog/zyxel-nas-critical-vulnerabilities/; reference:cve,2024-29972; classtype:web-application-activity; sid:2055907; rev:1; metadata:affected_product Zyxel, tls_state plaintext, created_at 2024_09_18, cve CVE_2024_29972, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2024_09_18, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T11
Nuclei
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
nuclei·CVSS 9.8
CVE-2024-29972 [CRITICAL] Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Template:
id: CVE-2024-29972
info:
name: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account
author: gy741
severity: critical
description: |
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operat
Checkpoint
10th June – Threat Intelligence Report
blogs_checkpoint·2024-06-10
CVE-2024-4577 10th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th June, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Pathology services provider Synnovis has experienced a ransomware attack that affected procedures and operations in several major hospitals in London, including the Department of Health and Social Care, NHS Qilin (formerly Agenda) ransomware gang claimed responsibility for the attack.
Check Point Threat Emulation provides prot
Bleepingcomputer
Zyxel issues emergency RCE patch for end-of-life NAS devices
blogs_bleepingcomputer·2024-06-04·CVSS 9.8
[CRITICAL] Zyxel issues emergency RCE patch for end-of-life NAS devices
## Zyxel issues emergency RCE patch for end-of-life NAS devices
## Bill Toulas
Zyxel Networks has released an emergency security update to address three critical vulnerabilities impacting older NAS devices that have reached end-of-life.
The flaws impact NAS326 running firmware versions 5.21(AAZF.16)C0 and earlier, and NAS542 running firmware versions 5.21(ABAG.13)C0 and older.
The networking solutions vendor addressed three critical flaws, which enable attackers to perform command injection and remote code execution. However, two of the flaws allowing privilege escalation and information disclosure were not fixed in the end-of-life products.
Outpost24 security researcher Timothy Hjort discovered and reported all five vulnerabilities to Zyxel. Today, the researchers published a detaile
Greynoiseio
NoiseLetter November 2024
blogs_greynoiseio
NoiseLetter November 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter September 2024
blogs_greynoiseio
NoiseLetter September 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024
2024-06-04
Published
Exploited in the wild