### [CVE-2022-43391](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43391) ![](https://img.shields.io/static/v1?label=Product&message=NR7101%20firmware&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3C%20V1.15(ACCC.3)C0%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-120%3A%20Buffer%20Copy%20without%20Checking%20Size%20of%20Input%20('Classic%20Buffer%20Overflow')&color=brighgreen) ### Description A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request. ### POC #### Reference No PoCs from references. #### Github - https://github.com/karimhabush/cyberowl