CVE-2022-43389

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
ZyxelCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
zyxellte3202-m437_firmware
𝑥
< 1.00\(abwf.1\)c0
zyxellte3316-m604_firmware
𝑥
< 2.00\(abmp.6\)c0
zyxellte7480-m804_firmware
𝑥
< 1.00\(abra.6\)c0
zyxellte7490-m904_firmware
𝑥
< 1.00\(abqy.5\)c0
zyxelnebula_fwa510_firmware
𝑥
< 1.15\(acgd.3\)c0
zyxelnebula_fwa710_firmware
𝑥
< 1.15\(acgc.3\)c0
zyxelnebula_nr7101_firmware
𝑥
< 1.15\(accc.3\)c0
zyxelnr5103_firmware
𝑥
< 4.19\(abyc.3\)c0
zyxelnr5103e_firmware
-
zyxelnr7101_firmware
𝑥
< 1.00\(abuv.7\)c0
zyxelnr7102_firmware
𝑥
< 1.00\(abyd.2\)c0
zyxelnr7103_firmware
𝑥
< 1.00\(accz.1\)c0
zyxelep240p_firmware
-
zyxelpm7320-b0_firmware
-
zyxelpmg5317-t20b_firmware
-
zyxelpmg5617ga_firmware
-
zyxelpmg5622ga_firmware
-
𝑥
= Vulnerable software versions