CVE-2022-43443
19.12.2022, 03:15
OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially crafted request is sent to the management page.
Vendor | Product | Version |
---|---|---|
buffalo | wsr-3200ax4s_firmware | 𝑥 ≤ 1.26 |
buffalo | wsr-3200ax4b_firmware | 1.25 |
buffalo | wsr-2533dhp2_firmware | 𝑥 ≤ 1.22 |
buffalo | wsr-a2533dhp2_firmware | 𝑥 ≤ 1.22 |
buffalo | wsr-2533dhp3_firmware | 𝑥 ≤ 1.26 |
buffalo | wsr-a2533dhp3_firmware | 𝑥 ≤ 1.26 |
buffalo | wsr-2533dhpl2_firmware | 𝑥 ≤ 1.03 |
buffalo | wsr-2533dhpls_firmware | 𝑥 ≤ 1.07 |
buffalo | wsr-2533dhp_firmware | 𝑥 ≤ 1.08 |
buffalo | wsr-2533dhpl_firmware | 𝑥 ≤ 1.08 |
buffalo | wcr-1166ds_firmware | 𝑥 ≤ 1.34 |
𝑥
= Vulnerable software versions