PT-2023-1559 · Zyxel · Zyxel Nr7101
CVE-2022-43390
·
Publicado
2023-01-11
·
Atualizado
2023-01-18
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel NR7101 firmware versions prior to V1.15(ACCC.3)C0
Description
The issue exists due to the lack of measures to neutralize special elements used in the operating system command. Exploitation of this issue may allow a remote attacker to execute arbitrary commands using a specially crafted HTTP request. An authenticated attacker could execute some OS commands on a vulnerable device by sending a crafted HTTP request.
Recommendations
For Zyxel NR7101 firmware versions prior to V1.15(ACCC.3)C0, update to version V1.15(ACCC.3)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CGI program to minimize the risk of exploitation. Avoid using the vulnerable CGI program until the issue is resolved.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zyxel Nr7101