PT-2023-1559 · Zyxel · Zyxel Nr7101

CVE-2022-43390

·

Publicado

2023-01-11

·

Atualizado

2023-01-18

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel NR7101 firmware versions prior to V1.15(ACCC.3)C0
Description The issue exists due to the lack of measures to neutralize special elements used in the operating system command. Exploitation of this issue may allow a remote attacker to execute arbitrary commands using a specially crafted HTTP request. An authenticated attacker could execute some OS commands on a vulnerable device by sending a crafted HTTP request.
Recommendations For Zyxel NR7101 firmware versions prior to V1.15(ACCC.3)C0, update to version V1.15(ACCC.3)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CGI program to minimize the risk of exploitation. Avoid using the vulnerable CGI program until the issue is resolved.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01024
CVE-2022-43390

Produtos afetados

Zyxel Nr7101