CVE-2022-43466
19.12.2022, 03:15
OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command if a specially crafted request is sent to a specific CGI program.
Vendor | Product | Version |
---|---|---|
buffalo | wsr-3200ax4s_firmware | 𝑥 ≤ 1.26 |
buffalo | wsr-3200ax4b_firmware | 1.25 |
buffalo | wsr-2533dhp2_firmware | 𝑥 ≤ 1.22 |
buffalo | wsr-a2533dhp2_firmware | 𝑥 ≤ 1.22 |
buffalo | wsr-2533dhp3_firmware | 𝑥 ≤ 1.26 |
buffalo | wsr-a2533dhp3_firmware | 𝑥 ≤ 1.26 |
buffalo | wsr-2533dhpl2_firmware | 𝑥 ≤ 1.03 |
buffalo | wsr-2533dhpls_firmware | 𝑥 ≤ 1.07 |
buffalo | wex-1800ax4_firmware | 𝑥 ≤ 1.13 |
buffalo | wex-1800ax4ea_firmware | 𝑥 ≤ 1.13 |
𝑥
= Vulnerable software versions