CVE-2022-39044
07.12.2022, 10:15
Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and earlier, WPL-05G300 firmware Ver. 1.88 and earlier, WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, WZR-HP-AG300H firmware Ver. 1.76 and earlier, WZR-HP-G302H firmware Ver. 1.86 and earlier, WLAE-AG300N firmware Ver. 1.86 and earlier, FS-600DHP firmware Ver. 3.40 and earlier, FS-G300N firmware Ver. 3.14 and earlier, FS-HP-G300N firmware Ver. 3.33 and earlier, FS-R600DHP firmware Ver. 3.40 and earlier, BHR-4GRV firmware Ver. 2.00 and earlier, DWR-HP-G300NH firmware Ver. 1.84 and earlier, DWR-PG firmware Ver. 1.83 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WER-A54G54 firmware Ver. 1.43 and earlier, WER-AG54 firmware Ver. 1.43 and earlier, WER-AM54G54 firmware Ver. 1.43 and earlier, WER-AMG54 firmware Ver. 1.43 and earlier, WHR-300 firmware Ver. 2.00 and earlier, WHR-300HP firmware Ver. 2.00 and earlier, WHR-AM54G54 firmware Ver. 1.43 and earlier, WHR-AMG54 firmware Ver. 1.43 and earlier, WHR-AMPG firmware Ver. 1.52 and earlier, WHR-G firmware Ver. 1.49 and earlier, WHR-G300N firmware Ver. 1.65 and earlier, WHR-G301N firmware Ver. 1.87 and earlier, WHR-G54S firmware Ver. 1.43 and earlier, WHR-G54S-NI firmware Ver. 1.24 and earlier, WHR-HP-AMPG firmware Ver. 1.43 and earlier, WHR-HP-G firmware Ver. 1.49 and earlier, WHR-HP-G54 firmware Ver. 1.43 and earlier, WLI-H4-D600 firmware Ver. 1.88 and earlier, WLI-TX4-AG300N firmware Ver. 1.53 and earlier, WS024BF firmware Ver. 1.60 and earlier, WS024BF-NW firmware Ver. 1.60 and earlier, WZR2-G108 firmware Ver. 1.33 and earlier, WZR2-G300N firmware Ver. 1.55 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, WZR-AGL300NH firmware Ver. 1.55 and earlier, WZR-AMPG144NH firmware Ver. 1.49 and earlier, WZR-AMPG300NH firmware Ver. 1.51 and earlier, WZR-D1100H firmware Ver. 2.00 and earlier, WZR-G144N firmware Ver. 1.48 and earlier, WZR-G144NH firmware Ver. 1.48 and earlier, WZR-HP-G300NH firmware Ver. 1.84 and earlier, WZR-HP-G301NH firmware Ver. 1.84 and earlier, and WZR-HP-G450H firmware Ver. 1.90 and earlier.Enginsight
Vendor | Product | Version |
---|---|---|
buffalo | wcr-300_firmware | 𝑥 ≤ 1.87 |
buffalo | whr-hp-g300n_firmware | 𝑥 ≤ 2.00 |
buffalo | whr-hp-gn_firmware | 𝑥 ≤ 1.87 |
buffalo | wpl-05g300_firmware | 𝑥 ≤ 1.88 |
buffalo | wzr-300hp_firmware | 𝑥 ≤ 2.00 |
buffalo | wzr-450hp_firmware | 𝑥 ≤ 2.00 |
buffalo | wzr-600dhp_firmware | 𝑥 ≤ 2.00 |
buffalo | wzr-900dhp_firmware | 𝑥 ≤ 1.15 |
buffalo | wzr-hp-ag300h_firmware | 𝑥 ≤ 1.76 |
buffalo | wzr-hp-g302h_firmware | 𝑥 ≤ 1.86 |
buffalo | wlae-ag300n_firmware | 𝑥 ≤ 1.86 |
buffalo | fs-600dhp_firmware | 𝑥 ≤ 3.40 |
buffalo | fs-g300n_firmware | 𝑥 ≤ 3.14 |
buffalo | fs-hp-g300n_firmware | 𝑥 ≤ 3.33 |
buffalo | fs-r600dhp_firmware | 𝑥 ≤ 3.40 |
buffalo | bhr-4grv_firmware | 𝑥 ≤ 2.00 |
buffalo | dwr-hp-g300nh_firmware | 𝑥 ≤ 1.84 |
buffalo | dwr-pg_firmware | 𝑥 ≤ 1.83 |
buffalo | hw-450hp-zwe_firmware | 𝑥 ≤ 2.00 |
buffalo | wer-a54g54_firmware | 𝑥 ≤ 1.43 |
buffalo | wer-ag54_firmware | 𝑥 ≤ 1.43 |
buffalo | wer-am54g54_firmware | 𝑥 ≤ 1.43 |
buffalo | wer-amg54_firmware | 𝑥 ≤ 1.43 |
buffalo | whr-300_firmware | 𝑥 ≤ 2.00 |
buffalo | whr-300hp_firmware | 𝑥 ≤ 2.00 |
buffalo | whr-am54g54_firmware | 𝑥 ≤ 1.43 |
buffalo | whr-amg54_firmware | 𝑥 ≤ 1.43 |
buffalo | whr-ampg_firmware | 𝑥 ≤ 1.52 |
buffalo | whr-g_firmware | 𝑥 ≤ 1.49 |
buffalo | whr-g300n_firmware | 𝑥 ≤ 1.65 |
buffalo | whr-g301n_firmware | 𝑥 ≤ 1.87 |
buffalo | whr-g54s_firmware | 𝑥 ≤ 1.43 |
buffalo | whr-g54s-ni_firmware | 𝑥 ≤ 1.24 |
buffalo | whr-hp-ampg_firmware | 𝑥 ≤ 1.49 |
buffalo | whr-hp-g_firmware | 𝑥 ≤ 1.49 |
buffalo | whr-hp-g54_firmware | 𝑥 ≤ 1.43 |
buffalo | wli-h4-d600_firmware | 𝑥 ≤ 1.88 |
buffalo | wli-tx4-ag300n_firmware | 𝑥 ≤ 1.53 |
buffalo | ws024bf_firmware | 𝑥 ≤ 1.60 |
buffalo | ws024bf-nw_firmware | 𝑥 ≤ 1.60 |
buffalo | wzr2-g108_firmware | 𝑥 ≤ 1.33 |
buffalo | wzr2-g300n_firmware | 𝑥 ≤ 1.55 |
buffalo | wzr-450hp-cwt_firmware | 𝑥 ≤ 2.00 |
buffalo | wzr-450hp-ub_firmware | 𝑥 ≤ 2.00 |
buffalo | wzr-600dhp2_firmware | 𝑥 ≤ 1.15 |
buffalo | wzr-agl300nh_firmware | 𝑥 ≤ 1.55 |
buffalo | wzr-ampg144nh_firmware | 𝑥 ≤ 1.49 |
buffalo | wzr-ampg300nh_firmware | 𝑥 ≤ 1.51 |
buffalo | wzr-d1100h_firmware | 𝑥 ≤ 2.00 |
buffalo | wzr-g144n_firmware | 𝑥 ≤ 1.48 |
buffalo | wzr-g144nh_firmware | 𝑥 ≤ 1.48 |
buffalo | wzr-hp-g300nh_firmware | 𝑥 ≤ 1.84 |
buffalo | wzr-hp-g301nh_firmware | 𝑥 ≤ 1.84 |
buffalo | wzr-hp-g450h_firmware | 𝑥 ≤ 1.90 |
𝑥
= Vulnerable software versions