HIGH · 8.6

CVE-2022-43389

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to caus...

Vulnerability Description

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
ZyxelLte3202-M437 Firmware< 1.00\(abwf.1\)c0
ZyxelLte3202-M437-
ZyxelLte3316-M604 Firmware< 2.00\(abmp.6\)c0
ZyxelLte3316-M604-
ZyxelLte7480-M804 Firmware< 1.00\(abra.6\)c0
ZyxelLte7480-M804-
ZyxelLte7490-M904 Firmware< 1.00\(abqy.5\)c0
ZyxelLte7490-M904-
ZyxelNebula Fwa510 Firmware< 1.15\(acgd.3\)c0
ZyxelNebula Fwa510-
ZyxelNebula Fwa710 Firmware< 1.15\(acgc.3\)c0
ZyxelNebula Fwa710-
ZyxelNebula Nr7101 Firmware< 1.15\(accc.3\)c0
ZyxelNebula Nr7101-
ZyxelNr5103 Firmware< 4.19\(abyc.3\)c0
ZyxelNr5103-
ZyxelNr5103E Firmware-
ZyxelNr5103E-
ZyxelNr7101 Firmware< 1.00\(abuv.7\)c0
ZyxelNr7101-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-43389?

CVE-2022-43389 is a vulnerability with a CVSS score of 8.6 (HIGH). A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to caus...

How severe is CVE-2022-43389?

CVE-2022-43389 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-43389?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Lte3202-M437 Firmware, Zyxel Lte3202-M437, Zyxel Lte3316-M604 Firmware, Zyxel Lte3316-M604, Zyxel Lte7480-M804 Firmware.