ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Zyxel fixes critical command injection flaw in EOL NAS devices (CVE-2024-6342)

criticalVulnerability exploited in the wildimportance 60CVE-2024-6342CVE-2024-29973

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and N

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

NVD description · AI analysis pending
9.886% PoC
  • zyxel nas326 firmware
  • zyxel nas542 firmware
CVE-2024-6342
**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

NVD description · AI analysis pending
9.82%
  • zyxel nas326 firmware
  • zyxel nas542 firmware
Full article202 words · extracted from helpnetsecurity.com · click to collapse

Users of Zyxel network-attached storage (NAS) devices are urged to implement hotfixes addressing a critical and easily exploited command injection vulnerability (CVE-2024-6342).

CVE-2024-6342

About CVE-2024-6342

Zyxel NAS devices are generally used by small to medium-sized businesses (SMBs) for data storage and backup.

CVE-2024-6342 – reported by Nanyu Zhong and Jinwei Dong from VARAS@IIE – is a vulnerability in the export-cgi program of Zyxel NAS326 and NAS542 devices that can be triggered by unauthenticated attackers via a specially crafted HTTP POST request, and may allow them to execute some operating system commands.

“Due to the critical severity of the vulnerability, Zyxel has made hotfixes available to customers with extended support as outlined in the table below, despite the products already having reached end-of-vulnerability-support,” the company said.

Zyxel doesn’t say whether the vulnerability is under active exploitation, but urges users to install the hotfixes “for optimal protection.”

NAS devices are an attractive target for cyber criminals. Earlier this year, a Mirai-like botnet has been spotted trying to leverage another command injection vulnerability (CVE-2024-29973) that Zyxel has fixed in these same end-of-life NAS devices.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/10/cve-2024-6342/