Vulnerability record · CVE-2024-29973 · published 4 June 2024
CVE-2024-29973: Zyxel NAS setCookie parameter OS command injection
Zyxel · Nas326 Firmware
Zyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affected firmware versions are before V5.21(AAZF.17)C0 for NAS326 and before V5.21(ABAG.14)C0 for NAS542. Because it is unauthenticated and network-reachable, it is a severe pre-auth remote code execution risk for exposed NAS devices.
Description
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable OS command injection with CVSS 9.8 and very high EPSS, plus public exploit references, makes this an urgent patch-or-isolate case.
What it is
Zyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affected firmware versions are before V5.21(AAZF.17)C0 for NAS326 and before V5.21(ABAG.14)C0 for NAS542. Because it is unauthenticated and network-reachable, it is a severe pre-auth remote code execution risk for exposed NAS devices.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the device, leading to full compromise of confidentiality, integrity and availability. This can expose stored data and allow the NAS to be used as a foothold into the network.
Attack surface
Reached over the network through an HTTP POST request to the vulnerable setCookie parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or LAN-exposed management interface on an unpatched device is a candidate entry point.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.86089, 99.7th percentile) and a third-party advisory is tagged Exploit, indicating public exploit detail exists. No ransomware group usage is documented in the record.
What to do
- Upgrade NAS326 to V5.21(AAZF.17)C0 or later and NAS542 to V5.21(ABAG.14)C0 or later per the Zyxel advisory.
- If patching cannot be done immediately, remove the devices from internet exposure and restrict management access to trusted networks only.
- Segment NAS devices from critical systems and limit outbound traffic to reduce post-exploitation movement.
- Monitor the vendor advisory for updated fixed firmware and apply it as soon as available.
Detection
- Inspect HTTP POST request logs for suspicious or malformed setCookie parameter values.
- Alert on unexpected child processes or shell activity spawned by the NAS web service.
- Monitor for outbound connections from NAS devices to unknown hosts, which may indicate command-and-control or data exfiltration.
- Review authentication and access logs for anomalous requests to the NAS management interface from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/ | ExploitThird Party Advisory |
| https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas- | Vendor Advisory |
| https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/ | ExploitThird Party Advisory |
| https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas- | Vendor Advisory |
Track CVE-2024-29973 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-29973), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.