CVE-2024-29975

EUVD-2024-26949
** UNSUPPORTED WHEN ASSIGNED **
The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a vulnerable device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 38.58%
Affected Products (NVD)
VendorProductVersion
zyxelnas326_firmware
𝑥
< 5.21\(aazf.17\)c0
zyxelnas542_firmware
𝑥
< 5.21\(abag.14\)c0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
zyxelnas326_firmware
𝑥
< v5.21\(aazf.17\)co
ADP
zyxelnas542_firmware
𝑥
< 5.21\(abag.14\)co
ADP