PT-2024-4080 · Zyxel · Zyxel Nas542+1

Timothy Hjort

·

Published

2024-06-03

·

Updated

2025-01-22

·

CVE-2024-29976

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zyxel NAS326 versions prior to V5.21(AAZF.17)C0 Zyxel NAS542 versions prior to V5.21(ABAG.14)C0
Description The issue concerns improper privilege management in the command show allsessions in Zyxel NAS326 and NAS542 firmware. This could allow an authenticated attacker to obtain a logged-in administrator's session information containing cookies on an affected device by sending a specially crafted GET request to the /cmd,/ck6fup6/system main/show allsessions endpoint. The show allsessions command is vulnerable, potentially allowing attackers to elevate their privileges and gain unauthorized access to protected information.
Recommendations For Zyxel NAS326 versions prior to V5.21(AAZF.17)C0, update the firmware to V5.21 or later. For Zyxel NAS542 versions prior to V5.21(ABAG.14)C0, update the firmware to V5.21 or later. As a temporary workaround, consider restricting access to the show allsessions command until a patch is available. Avoid using the vulnerable endpoint /cmd,/ck6fup6/system main/show allsessions in the affected firmware versions to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04529
CVE-2024-29976

Affected Products

Zyxel Nas326
Zyxel Nas542