CVE-2022-43486
6.8
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug functionalities and execute an arbitrary command on the affected devices.
Affected (13)
Products: Buffalo: Wsr 3200ax4s Firmware, Wsr 3200ax4b Firmware, Wsr 2533dhp2 Firmware, Wsr A2533dhp2 Firmware, Wsr 2533dhp3 Firmware, Wsr A2533dhp3 Firmware, Wsr 2533dhpl2 Firmware, Wsr 2533dhpls Firmware, Wex 1800ax4 Firmware, Wex 1800ax4ea Firmware, Wsr 2533dhp Firmware, Wsr 2533dhpl Firmware, Wcr 1166ds Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.26 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 3200ax4s | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.25 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 3200ax4b | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.22 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 2533dhp2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.22 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr A2533dhp2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.26 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 2533dhp3 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.26 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr A2533dhp3 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.03 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 2533dhpl2 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.07 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 2533dhpls | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.13 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wex 1800ax4 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.13 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wex 1800ax4ea | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.08 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 2533dhp | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.08 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wsr 2533dhpl | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.34 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wcr 1166ds | All versions |
References (4)
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.