Vulnerability record · CVE-2024-29972 · published 4 June 2024
CVE-2024-29972: Zyxel NAS remote_help-cgi unauthenticated OS command injection
Zyxel · Nas326 Firmware
The remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. The flaw is unauthenticated and network-reachable, so any exposed device can be attacked without credentials. Zyxel marks the affected products as unsupported when assigned, meaning no vendor fix is expected for these models.
Description
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable OS command injection with CVSS 9.8 and very high EPSS on unsupported devices that may remain deployed.
What it is
The remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. The flaw is unauthenticated and network-reachable, so any exposed device can be attacked without credentials. Zyxel marks the affected products as unsupported when assigned, meaning no vendor fix is expected for these models.
Impact
An attacker can execute arbitrary operating system commands on the NAS with the privileges of the CGI process, leading to full device compromise, data theft or use as a foothold into the network.
Attack surface
Reachable over the network through HTTP POST requests to the remote_help-cgi endpoint; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.893, 99.8th percentile) and a third-party advisory is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.
What to do
- Apply the Zyxel firmware updates if still available: NAS326 V5.21(AAZF.17)C0 or later and NAS542 V5.21(ABAG.14)C0 or later.
- Because the products are unsupported, isolate or retire affected NAS devices; do not expose them to the internet.
- Restrict management and web access to trusted internal networks via firewall rules or VLAN segmentation.
- Monitor vendor advisory and third-party research for any further guidance or workarounds.
Detection
- Inspect HTTP logs for POST requests to remote_help-cgi, especially with shell metacharacters or unexpected parameters.
- Alert on unexpected child processes spawned by the web/CGI service (shell, wget, curl, nc) on NAS hosts.
- Monitor outbound connections from NAS devices to unfamiliar external IPs or unusual ports.
- Review NAS system logs and file integrity for signs of command execution or persistence.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/ | ExploitThird Party Advisory |
| https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas- | Vendor Advisory |
| https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/ | ExploitThird Party Advisory |
| https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas- | Vendor Advisory |
Track CVE-2024-29972 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-29972), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.