mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
22 lines
1.4 KiB
Markdown
22 lines
1.4 KiB
Markdown
### [CVE-2024-29972](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29972)
|
||

|
||

|
||
C0%20&color=brighgreen)
|
||
C0%20&color=brighgreen)
|
||
&color=brighgreen)
|
||
|
||
### Description
|
||
|
||
** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED **The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/
|
||
|
||
#### Github
|
||
- https://github.com/Pommaq/CVE-2024-29972-CVE-2024-29976-CVE-2024-29973-CVE-2024-29975-CVE-2024-29974-poc
|
||
- https://github.com/WanLiChangChengWanLiChang/CVE-2024-29972
|
||
- https://github.com/nomi-sec/PoC-in-GitHub
|
||
|