Description
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
Published: 2023-01-11
Score: 5.4 Medium
EPSS: 2.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-46429 A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
History

Tue, 08 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Zyxel Ax7501-b0 Ax7501-b0 Firmware Dx3301-t0 Dx3301-t0 Firmware Dx4510-b1 Dx4510-b1 Firmware Dx5401-b0 Dx5401-b0 Firmware Emg3525-t50b Emg3525-t50b Firmware Emg5523-t50b Emg5523-t50b Firmware Emg5723-t50k Emg5723-t50k Firmware Ex3301-t0 Ex3301-t0 Firmware Ex3510-b0 Ex3510-b0 Firmware Ex5401-b0 Ex5401-b0 Firmware Ex5501-b0 Ex5501-b0 Firmware Ex5510-b0 Ex5510-b0 Firmware Ex5512-t0 Ex5512-t0 Firmware Ex5600-t1 Ex5600-t1 Firmware Ex5601-t0 Ex5601-t0 Firmware Ex5601-t1 Ex5601-t1 Firmware Lte7480-m804 Lte7480-m804 Firmware Lte7490-m904 Lte7490-m904 Firmware Nebula Nr5101 Nebula Nr5101 Firmware Nebula Nr7101 Nebula Nr7101 Firmware Nr5101 Nr5101 Firmware Nr7101 Nr7101 Firmware Nr7102 Nr7102 Firmware Pm3100-t0 Pm3100-t0 Firmware Pm5100-t0 Pm5100-t0 Firmware Pm7300-t0 Pm7300-t0 Firmware Pm7320-b0 Pm7320-b0 Firmware Pmg5317-t20b Pmg5317-t20b Firmware Pmg5617-t20b2 Pmg5617-t20b2 Firmware Pmg5617ga Pmg5617ga Firmware Pmg5622ga Pmg5622ga Firmware Vmg3927-t50k Vmg3927-t50k Firmware Vmg4005-b50a Vmg4005-b50a Firmware Vmg4005-b60a Vmg4005-b60a Firmware Vmg8623-t50b Vmg8623-t50b Firmware Vmg8825-t50k Vmg8825-t50k Firmware Wx3100-t0 Wx3100-t0 Firmware Wx3401-b0 Wx3401-b0 Firmware Wx5600-t0 Wx5600-t0 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2025-04-08T20:16:36.803Z

Reserved: 2022-10-18T00:00:00.000Z

Link: CVE-2022-43390

cve-icon Vulnrichment

Updated: 2024-08-03T13:32:57.394Z

cve-icon NVD

Status : Modified

Published: 2023-01-11T02:15:11.170

Modified: 2024-11-21T07:26:23.043

Link: CVE-2022-43390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses