cve/2024/CVE-2024-29976.md
2024-07-25 21:25:12 +00:00

1.1 KiB
Raw Permalink Blame History

CVE-2024-29976

Description

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED **The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrators session information containing cookies on an affected device.

POC

Reference

Github