CVE-2022-43390
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
Affected (39)
Products: Zyxel: Lte7480 M804 Firmware, Lte7490 M904 Firmware, Nebula Nr5101 Firmware, Nebula Nr7101 Firmware, Nr5101 Firmware, Nr7101 Firmware, Nr7102 Firmware, Dx3301 T0 Firmware, Dx4510 B1 Firmware, Dx5401 B0 Firmware, Emg3525 T50b Firmware, Emg5523 T50b Firmware, Emg5723 T50k Firmware, Ex3301 T0 Firmware, Ex3510 B0 Firmware, Ex5401 B0 Firmware, Ex5501 B0 Firmware, Ex5510 B0 Firmware, Ex5512 T0 Firmware, Ex5600 T1 Firmware, Ex5601 T0 Firmware, Ex5601 T1 Firmware, Vmg3927 T50k Firmware, Vmg4005 B50a Firmware, Vmg4005 B60a Firmware, Vmg8623 T50b Firmware, Vmg8825 T50k Firmware, Ax7501 B0 Firmware, Pm3100 T0 Firmware, Pm5100 T0 Firmware, Pm7300 T0 Firmware, Pm7320 B0 Firmware, Pmg5317 T20b Firmware, Pmg5617 T20b2 Firmware, Pmg5617ga Firmware, Pmg5622ga Firmware, Wx3100 T0 Firmware, Wx3401 B0 Firmware, Wx5600 T0 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.00\(abra.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Lte7480 M804 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.00\(abqy.5\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Lte7490 M904 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.15\(accg.3\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nebula Nr5101 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.15\(accc.3\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nebula Nr7101 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.00\(abvc.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nr5101 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.00\(abuv.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nr7101 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.00\(abyd.2\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nr7102 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Dx3301 T0 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Dx4510 B1 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Dx5401 B0 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Emg3525 T50b | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Emg5523 T50b | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Emg5723 T50k | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex3301 T0 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abup.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex3510 B0 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5401 B0 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5501 B0 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abqx.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5510 B0 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5512 T0 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5600 T1 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5601 T0 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5601 T1 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg3927 T50k | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg4005 B50a | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg4005 B60a | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8623 T50b | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8825 T50k | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ax7501 B0 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pm3100 T0 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pm5100 T0 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pm7300 T0 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pm7320 B0 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5317 T20b | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5617 T20b2 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5617ga | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5622ga | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wx3100 T0 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wx3401 B0 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wx5600 T0 | All versions |
References (2)
Source: security@zyxel.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.