CVE-2022-43389
published 2023-01-11CVE-2022-43389: A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | lte3202-m437_firmware | < 1.00\(abwf.1\)c0 | 1.00\(abwf.1\)c0 |
| zyxel | lte3316-m604_firmware | < 2.00\(abmp.6\)c0 | 2.00\(abmp.6\)c0 |
| zyxel | lte7480-m804_firmware | < 1.00\(abra.6\)c0 | 1.00\(abra.6\)c0 |
| zyxel | lte7490-m904_firmware | < 1.00\(abqy.5\)c0 | 1.00\(abqy.5\)c0 |
| zyxel | nebula_fwa510_firmware | < 1.15\(acgd.3\)c0 | 1.15\(acgd.3\)c0 |
| zyxel | nebula_fwa710_firmware | < 1.15\(acgc.3\)c0 | 1.15\(acgc.3\)c0 |
| zyxel | nebula_nr7101_firmware | < 1.15\(accc.3\)c0 | 1.15\(accc.3\)c0 |
| zyxel | nr5103_firmware | < 4.19\(abyc.3\)c0 | 4.19\(abyc.3\)c0 |
| zyxel | nr7101_firmware | < V1.15(ACCC.3)C0 | V1.15(ACCC.3)C0 |
| zyxel | nr7101_firmware | < 1.00\(abuv.7\)c0 | 1.00\(abuv.7\)c0 |
| zyxel | nr7102_firmware | < 1.00\(abyd.2\)c0 | 1.00\(abyd.2\)c0 |
| zyxel | nr7103_firmware | < 1.00\(accz.1\)c0 | 1.00\(accz.1\)c0 |