CVE-2024-44072

EUVD-2024-40849
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.7 MEDIUM
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
buffalo_incwhr_1166dhp2
𝑥
≤ 2.95
ADP
buffalo_incwhr_1166dhp3
𝑥
≤ 2.95
ADP
buffalo_incwhr_1166dhp4
𝑥
≤ 2.95
ADP
buffalo_incwsr_1166dhp3
𝑥
≤ 1.18
ADP
buffalo_incwsr_600dhp
𝑥
≤ 2.93
ADP
buffalo_incwex_300hptxn
𝑥
≤ 1.02
ADP
buffalo_incwex_733dhp2
𝑥
≤ 1.03
ADP
buffalo_incwex_1166dhp2
𝑥
≤ 1.05
ADP
buffalo_incwex_1166dhps
𝑥
≤ 1.05
ADP
buffalo_incwex_300hpsn
𝑥
≤ 1.02
ADP
buffalo_incwex_733dhps
𝑥
≤ 1.02
ADP
buffalo_incwex_733hptx
𝑥
≤ 1.03
ADP
buffalo_incwex_1166dhp
𝑥
≤ 1.23
ADP
buffalo_incwex_733dhp
𝑥
≤ 1.64
ADP
buffalo_incwhr_1166dhp
𝑥
≤ 2.92
ADP
buffalo_incwhr_300hp2
𝑥
≤ 2.51
ADP
buffalo_incwhr_600d
𝑥
≤ 2.91
ADP
buffalo_incwmr_300
𝑥
≤ 2.50
ADP