logo

Emergency patches released for critical vulns impacting EOL Zyxel NAS boxes

ID: cad2e6b0-d0fb-59cf-a2b5-462ae074131b

STIX ID: report--cad2e6b0-d0fb-59cf-a2b5-462ae074131b

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-06-05

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Zyxel released security fixes for critical vulnerabilities in NAS326 and NAS542 (EOL) firmware after an Outpost24 intern reported five bugs, including three critical RCEs (CVEs 2024-29972/29973/29974) — a backdoor 'NsaRescueAngel', a Python code-injection endpoint, and an RCE affecting the file_upload-cgi leading to persistence. Proof-of-concept code was published, patches were issued for extended-support customers, and there is no confirmed evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.