CVE-2024-22366
24.01.2024, 05:15
Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.
Vendor | Product | Version |
---|---|---|
yamaha | wlx222_firmware | 𝑥 < 24.00.04 |
yamaha | wlx413_firmware | 𝑥 < 22.00.06 |
yamaha | wlx212_firmware | 𝑥 < 21.00.13 |
yamaha | wlx313_firmware | 𝑥 < 18.00.13 |
yamaha | wlx202_firmware | 𝑥 < 16.00.19 |
𝑥
= Vulnerable software versions