CVE-2022-43389
Summary
| CVE | CVE-2022-43389 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-11 02:15:00 UTC |
| Updated | 2023-01-18 21:48:00 UTC |
| Description | A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device. |
Risk And Classification
Problem Types: CWE-120
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Zyxel | Ep240p | - | All | All | All |
| Operating System | Zyxel | Ep240p Firmware | - | All | All | All |
| Hardware | Zyxel | Lte3202-m437 | - | All | All | All |
| Operating System | Zyxel | Lte3202-m437 Firmware | All | All | All | All |
| Hardware | Zyxel | Lte3316-m604 | - | All | All | All |
| Operating System | Zyxel | Lte3316-m604 Firmware | All | All | All | All |
| Hardware | Zyxel | Lte7480-m804 | - | All | All | All |
| Operating System | Zyxel | Lte7480-m804 Firmware | All | All | All | All |
| Hardware | Zyxel | Lte7490-m904 | - | All | All | All |
| Operating System | Zyxel | Lte7490-m904 Firmware | All | All | All | All |
| Hardware | Zyxel | Nebula Fwa510 | - | All | All | All |
| Operating System | Zyxel | Nebula Fwa510 Firmware | All | All | All | All |
| Hardware | Zyxel | Nebula Fwa710 | - | All | All | All |
| Operating System | Zyxel | Nebula Fwa710 Firmware | All | All | All | All |
| Hardware | Zyxel | Nebula Nr7101 | - | All | All | All |
| Operating System | Zyxel | Nebula Nr7101 Firmware | All | All | All | All |
| Hardware | Zyxel | Nr5103 | - | All | All | All |
| Hardware | Zyxel | Nr5103e | - | All | All | All |
| Operating System | Zyxel | Nr5103e Firmware | - | All | All | All |
| Operating System | Zyxel | Nr5103 Firmware | All | All | All | All |
| Hardware | Zyxel | Nr7101 | - | All | All | All |
| Operating System | Zyxel | Nr7101 Firmware | All | All | All | All |
| Hardware | Zyxel | Nr7102 | - | All | All | All |
| Operating System | Zyxel | Nr7102 Firmware | All | All | All | All |
| Hardware | Zyxel | Nr7103 | - | All | All | All |
| Operating System | Zyxel | Nr7103 Firmware | All | All | All | All |
| Hardware | Zyxel | Pm7320-b0 | - | All | All | All |
| Operating System | Zyxel | Pm7320-b0 Firmware | - | All | All | All |
| Hardware | Zyxel | Pmg5317-t20b | - | All | All | All |
| Operating System | Zyxel | Pmg5317-t20b Firmware | - | All | All | All |
| Hardware | Zyxel | Pmg5617ga | - | All | All | All |
| Operating System | Zyxel | Pmg5617ga Firmware | - | All | All | All |
| Hardware | Zyxel | Pmg5622ga | - | All | All | All |
| Operating System | Zyxel | Pmg5622ga Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zyxel security advisory for command injection and buffer overflow vulnerabilities of CPE, fiber ONTs, and WiFi extenders | Zyxel Networks | CONFIRM | www.zyxel.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.