PT-2024-4079 · Zyxel · Zyxel Nas542+1

Timothy Hjort

·

Published

2024-06-03

·

Updated

2025-01-22

·

CVE-2024-29975

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel NAS326 versions prior to V5.21(AAZF.17)C0 Zyxel NAS542 versions prior to V5.21(ABAG.14)C0
Description The issue is related to improper privilege management in the SUID executable binary. This could allow an authenticated local attacker with administrator privileges to execute system commands as the "root" user on a vulnerable device. The vulnerability is associated with deficiencies in access control, which may enable an attacker to elevate their privileges and execute arbitrary commands using the executor su binary file.
Recommendations For Zyxel NAS326 versions prior to V5.21(AAZF.17)C0, update to version V5.21(AAZF.17)C0 or later. For Zyxel NAS542 versions prior to V5.21(ABAG.14)C0, update to version V5.21(ABAG.14)C0 or later. As a temporary workaround, consider restricting access to the executor su binary file to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-04528
CVE-2024-29975

Affected Products

Zyxel Nas326
Zyxel Nas542