MEDIUM · 5.4

CVE-2022-43390

A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device b...

Vulnerability Description

A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ZyxelLte7480-M804 Firmware< 1.00\(abra.6\)c0
ZyxelLte7480-M804-
ZyxelLte7490-M904 Firmware< 1.00\(abqy.5\)c0
ZyxelLte7490-M904-
ZyxelNebula Nr5101 Firmware< 1.15\(accg.3\)c0
ZyxelNebula Nr5101-
ZyxelNebula Nr7101 Firmware< 1.15\(accc.3\)c0
ZyxelNebula Nr7101-
ZyxelNr5101 Firmware< 1.00\(abvc.6\)c0
ZyxelNr5101-
ZyxelNr7101 Firmware< 1.00\(abuv.7\)c0
ZyxelNr7101-
ZyxelNr7102 Firmware< 1.00\(abyd.2\)c0
ZyxelNr7102-
ZyxelDx3301-T0 Firmware-
ZyxelDx3301-T0-
ZyxelDx4510-B1 Firmware-
ZyxelDx4510-B1-
ZyxelDx5401-B0 Firmware-
ZyxelDx5401-B0-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-43390?

CVE-2022-43390 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device b...

How severe is CVE-2022-43390?

CVE-2022-43390 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-43390?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Lte7480-M804 Firmware, Zyxel Lte7480-M804, Zyxel Lte7490-M904 Firmware, Zyxel Lte7490-M904, Zyxel Nebula Nr5101 Firmware.