Zyxel Vulnerabilities and Affected Products
Vulnerabilities associated with NR7101 firmware.
Products
Clear product- USG FLEX series firmware51 vulnerabilities
- ATP series firmware49 vulnerabilities
- VPN series firmware37 vulnerabilities
- USG FLEX 50(W) series firmware28 vulnerabilities
- USG20(W)-VPN series firmware28 vulnerabilities
- NAS326 firmware15 vulnerabilities
- NAS542 firmware14 vulnerabilities
- USG FLEX 50(W) firmware11 vulnerabilities
- nas326_firmware9 vulnerabilities
- nas542_firmware9 vulnerabilities
- usg_flex_50w_firmware9 vulnerabilities
- USG/ZyWALL series firmware8 vulnerabilities
- USG20(W)-VPN firmware8 vulnerabilities
- VMG8825-T50K firmware8 vulnerabilities
- VMG3625-T50B firmware7 vulnerabilities
- WAC500 firmware7 vulnerabilities
- atp800_firmware6 vulnerabilities
- usg_flex_700h_firmware6 vulnerabilities
- Multiple Firewalls5 vulnerabilities
- NBG-418N v2 firmware5 vulnerabilities
- NR7101 firmware5 vulnerabilities
- NWA50AX firmware5 vulnerabilities
- usg_flex_firmware5 vulnerabilities
- WBE660S firmware5 vulnerabilities
- ZyWALL/USG series firmware5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-27989MEDIUM | A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could allow a remote authenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. CWE-120Jun 5, 2023 | CVSS6.5v3.1 | EPSS1.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43391MEDIUM | A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request. CWE-120Jan 11, 2023 | CVSS6.5v3.1 | EPSS0.722% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43390MEDIUM | A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request. CWE-78Jan 11, 2023 | CVSS5.4v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43392MEDIUM | A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request. CWE-120Jan 11, 2023 | CVSS6.5v3.1 | EPSS0.619% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43389HIGH | A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device. CWE-120Jan 11, 2023 | CVSS8.6v3.1 | EPSS0.611% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |