← Vulnerability feed

Vulnerability record · CVE-2024-29973 · published 4 June 2024

CVE-2024-29973: Zyxel NAS setCookie parameter OS command injection

Zyxel · Nas326 Firmware

Zyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affected firmware versions are before V5.21(AAZF.17)C0 for NAS326 and before V5.21(ABAG.14)C0 for NAS542. Because it is unauthenticated and network-reachable, it is a severe pre-auth remote code execution risk for exposed NAS devices.

9.8 CVSS 3.1 Critical EPSS 86% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable OS command injection with CVSS 9.8 and very high EPSS, plus public exploit references, makes this an urgent patch-or-isolate case.

What it is

Zyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affected firmware versions are before V5.21(AAZF.17)C0 for NAS326 and before V5.21(ABAG.14)C0 for NAS542. Because it is unauthenticated and network-reachable, it is a severe pre-auth remote code execution risk for exposed NAS devices.

Impact

An unauthenticated attacker can execute arbitrary operating system commands on the device, leading to full compromise of confidentiality, integrity and availability. This can expose stored data and allow the NAS to be used as a foothold into the network.

Attack surface

Reached over the network through an HTTP POST request to the vulnerable setCookie parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or LAN-exposed management interface on an unpatched device is a candidate entry point.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.86089, 99.7th percentile) and a third-party advisory is tagged Exploit, indicating public exploit detail exists. No ransomware group usage is documented in the record.

What to do

  • Upgrade NAS326 to V5.21(AAZF.17)C0 or later and NAS542 to V5.21(ABAG.14)C0 or later per the Zyxel advisory.
  • If patching cannot be done immediately, remove the devices from internet exposure and restrict management access to trusted networks only.
  • Segment NAS devices from critical systems and limit outbound traffic to reduce post-exploitation movement.
  • Monitor the vendor advisory for updated fixed firmware and apply it as soon as available.

Detection

  • Inspect HTTP POST request logs for suspicious or malformed setCookie parameter values.
  • Alert on unexpected child processes or shell activity spawned by the NAS web service.
  • Monitor for outbound connections from NAS devices to unknown hosts, which may indicate command-and-control or data exfiltration.
  • Review authentication and access logs for anomalous requests to the NAS management interface from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-29973 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27992Zyxel NAS devices pre-auth OS command injectionZyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthentica…KEVEPSS 83%analysed9.8CVE-2020-9054ZyXEL NAS weblogin.cgi pre-auth command injectionZyXEL NAS devices running firmware 5.21 fail to sanitize the username parameter in the weblogin.cgi CGI executable, allowing OS command injection. Be…KEVEPSS 100%analysed9.8CVE-2024-6342Zyxel nas326 firmware os command injection vulnerability**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 …EPSS 2.1%9.8CVE-2024-29974Zyxel nas326 firmware unrestricted file upload vulnerability** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before…EPSS 23%9.8CVE-2024-29972Zyxel NAS remote_help-cgi unauthenticated OS command injectionThe remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. …EPSS 89%analysed9.8CVE-2023-4473Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C…EPSS 41%9.8CVE-2023-4474Zyxel nas326 firmware os command injection vulnerabilityThe improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version …EPSS 30%9.8CVE-2023-35138Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firm…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2024-29973), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.