cbcvebase.
CVE-2024-29976
published 2024-06-04

CVE-2024-29976: ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before…

PriorityP343medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
8.95%
94.7th percentile
** UNSUPPORTED WHEN ASSIGNED **
The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affected device.

Affected

4 ranges
VendorProductVersion rangeFixed in
zyxelnas326_firmware< V5.21(AAZF.17)C0V5.21(AAZF.17)C0
zyxelnas326_firmware< 5.21\(aazf.17\)c05.21\(aazf.17\)c0
zyxelnas542_firmware< V5.21(ABAG.14)C0V5.21(ABAG.14)C0
zyxelnas542_firmware< 5.21\(abag.14\)c05.21\(abag.14\)c0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.