CVE-2024-6342: Zyxel NAS326 Firmware

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

Affected products

  • Zyxel NAS326 Firmware: before 5.21\(aazf.18\)c0 (fixed in 5.21\(aazf.18\)c0); version 5.21(aazf.18)c0 only
  • Zyxel NAS542 Firmware: before 5.21\(abag.15\)c0 (fixed in 5.21\(abag.15\)c0); version 5.21(abag.15)c0 only

Published 2024-09-10. Last modified 2026-06-17.