Sploitus

Exploit for OS Command Injection in Zyxel Nas326 Firmware

githubexploit Β· 2024-06-20

Exploit Code

README13 lines
## https://sploitus.com/exploit?id=B0B17759-658A-52FA-A623-5E26C5367884
# TG Join Us: https://t.me/WanLiChangChengWanLiChang  
Join us for timely notifications of various vulnerabilities and exploits.  

# CVE-2024-29972-EXP  
CVE-2024-29972: The Zyxel NAS backdoor account was opened without authorization.  

# FOFA  
app="ZyXEL-NAS326"  

# Notes:  
This exploit utilizes scripts related to CVE-2024-29972 and CVE-2024-29973. It can also be referred to as a combined attack.  
The backdoor account, NsaRescueAngel, has root access.