← Vulnerability feed

Vulnerability record · CVE-2024-29972 · published 4 June 2024

CVE-2024-29972: Zyxel NAS remote_help-cgi unauthenticated OS command injection

Zyxel · Nas326 Firmware

The remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. The flaw is unauthenticated and network-reachable, so any exposed device can be attacked without credentials. Zyxel marks the affected products as unsupported when assigned, meaning no vendor fix is expected for these models.

9.8 CVSS 3.1 Critical EPSS 89% · top 0.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable OS command injection with CVSS 9.8 and very high EPSS on unsupported devices that may remain deployed.

What it is

The remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. The flaw is unauthenticated and network-reachable, so any exposed device can be attacked without credentials. Zyxel marks the affected products as unsupported when assigned, meaning no vendor fix is expected for these models.

Impact

An attacker can execute arbitrary operating system commands on the NAS with the privileges of the CGI process, leading to full device compromise, data theft or use as a foothold into the network.

Attack surface

Reachable over the network through HTTP POST requests to the remote_help-cgi endpoint; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.893, 99.8th percentile) and a third-party advisory is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.

What to do

  • Apply the Zyxel firmware updates if still available: NAS326 V5.21(AAZF.17)C0 or later and NAS542 V5.21(ABAG.14)C0 or later.
  • Because the products are unsupported, isolate or retire affected NAS devices; do not expose them to the internet.
  • Restrict management and web access to trusted internal networks via firewall rules or VLAN segmentation.
  • Monitor vendor advisory and third-party research for any further guidance or workarounds.

Detection

  • Inspect HTTP logs for POST requests to remote_help-cgi, especially with shell metacharacters or unexpected parameters.
  • Alert on unexpected child processes spawned by the web/CGI service (shell, wget, curl, nc) on NAS hosts.
  • Monitor outbound connections from NAS devices to unfamiliar external IPs or unusual ports.
  • Review NAS system logs and file integrity for signs of command execution or persistence.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-29972 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27992Zyxel NAS devices pre-auth OS command injectionZyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthentica…KEVEPSS 83%analysed9.8CVE-2020-9054ZyXEL NAS weblogin.cgi pre-auth command injectionZyXEL NAS devices running firmware 5.21 fail to sanitize the username parameter in the weblogin.cgi CGI executable, allowing OS command injection. Be…KEVEPSS 100%analysed9.8CVE-2024-6342Zyxel nas326 firmware os command injection vulnerability**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 …EPSS 2.1%9.8CVE-2024-29973Zyxel NAS setCookie parameter OS command injectionZyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affe…EPSS 86%analysed9.8CVE-2024-29974Zyxel nas326 firmware unrestricted file upload vulnerability** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before…EPSS 23%9.8CVE-2023-4473Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C…EPSS 41%9.8CVE-2023-4474Zyxel nas326 firmware os command injection vulnerabilityThe improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version …EPSS 30%9.8CVE-2023-35138Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firm…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2024-29972), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.