CVE-2024-29973 is an operating-system command-injection vulnerability in the setCookie parameter of Zyxel NAS326 firmware prior to V5.21(AAZF.17)C0 and NAS542 firmware prior to V5.21(ABAG.14)C0. An unauthenticated attacker can send a crafted HTTP POST request that causes the device to execute some operating-system commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Python exploit script (CVE-2024-29973.py) targeting a command injection vulnerability (CVE-2024-29973) in Zyxel NAS devices. The exploit works by sending a crafted HTTP GET request to a specific endpoint on the target device, injecting a Python command to execute 'id' via the device's backend. The script reads a list of target URLs from 'Kelpie.txt', attempts exploitation in parallel using threads, and writes any confirmed vulnerable URLs to 'vul_url.txt'. The README provides usage instructions and a sample HTTP request. The repository is structured simply, with one exploit script and a README, and is operational, providing real exploitation capability (not just detection).
This repository provides an asynchronous Python exploit tool targeting CVE-2024-29973, a command injection vulnerability. The main file, 'exploit.py', is a standalone script that can scan single or multiple URLs for the vulnerability. It constructs a specific HTTP GET request to the endpoint '/cmd,/simZysh/register_main/setCookie' with a crafted 'c0' parameter that attempts to inject and execute a Python command ('echo Exploited') on the target. If the response contains the string 'Exploited', the target is confirmed vulnerable. The tool supports proxying, multi-threaded scanning, and output to a file. The repository also includes a README with usage instructions and a requirements.txt for dependencies. No hardcoded IPs or domains are present; the user supplies targets via command line. The exploit is operational, providing real exploitation and confirmation of code execution, not just detection.
This repository is a comprehensive proof-of-concept exploit toolkit targeting multiple vulnerabilities (CVE-2024-29972 through CVE-2024-29976) in ZyXEL NAS devices, such as the NAS326. The main exploit script, 'exploit.py', is a command-line tool (using Typer) that provides several attack primitives: - Arbitrary Python code execution via command injection (CVE-2024-29973) - Privilege escalation to root using a local binary (CVE-2024-29975) - Extraction of sensitive information (CVE-2024-29976) - Enabling a backdoor account and SSH service (CVE-2024-29972) - Uploading a malicious configuration file to achieve persistence (CVE-2024-29974) The exploit interacts with the target device over HTTP, abusing endpoints such as '/cmd,/simZysh/register_main/setCookie' for code execution and '/desktop,/cgi-bin/file_upload-cgi/favicon.ico' for uploading malicious files. The included shell scripts ('create_rom.sh' and 'create_tar_archive.sh') are used to craft a malicious ROM/configuration archive, which, when uploaded, sets up a cronjob to create a file ('/tmp/pwned') as a marker of successful exploitation. The repository is structured as follows: - 'exploit.py': Main exploit script with multiple attack commands - 'create_rom.sh' and 'create_tar_archive.sh': Helper scripts for crafting malicious configuration payloads - 'magic.rom': Placeholder for the malicious ROM file - 'requirements.txt': Python dependencies Overall, this repository provides a multi-faceted attack toolkit for exploiting and persisting on vulnerable ZyXEL NAS devices.
This repository contains a Python proof-of-concept (PoC) exploit and bulk scanner for CVE-2024-29973, a command injection vulnerability affecting Zyxel NAS326 and NAS542 devices with outdated firmware. The main file, 'CVE-2024-29973.py', allows users to scan a single target or multiple targets (from a file) for the vulnerability. The exploit works by sending a specially crafted HTTP GET request to a vulnerable endpoint on the Zyxel NAS web interface, attempting to execute the 'id' command via Python's subprocess module. If successful, the script detects the presence of 'root:' in the response, indicating command execution as root. The script logs results to 'logs/scan.log' and provides colored terminal output for status messages. The README provides usage instructions, requirements, and references. No hardcoded IPs or domains are present; targets are user-supplied. The exploit is a functional PoC, not weaponized, and is intended for authorized security testing only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVE record whose template CVSS score metadata was being corrected to agree with its CVSS metrics vector and NVD's computed score.
A Python injection vulnerability in Zyxel NAS simZysh, for which detection artifacts and exploit code exist.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.