SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-43389

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable…

CRITICAL 9.8EPSS 0.61%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.61% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
zyxel/lte3202-m437 firmware · zyxel/lte3316-m604 firmware · zyxel/lte7480-m804 firmware · zyxel/lte7490-m904 firmware · zyxel/nebula fwa510 firmware · zyxel/nebula fwa710 firmware · zyxel/nebula nr7101 firmware · zyxel/nr5103 firmware · zyxel/nr5103e firmware · zyxel/nr7101 firmware · zyxel/nr7102 firmware · zyxel/nr7103 firmware · zyxel/ep240p firmware · zyxel/pm7320-b0 firmware · zyxel/pmg5317-t20b firmware · zyxel/pmg5617ga firmware · zyxel/pmg5622ga firmware
Source
security@zyxel.com.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.