OS Command Injection Vulnerability in Buffalo Network Devices
CVE-2022-43443

8.8HIGH

Key Information:

Vendor
CVE Published:
19 December 2022

What is CVE-2022-43443?

An OS command injection vulnerability exists in Buffalo network devices, enabling an attacker who is on the same network to execute arbitrary OS commands. By sending a specially crafted request to the management page, unauthorized actions can be performed, potentially compromising the device and the network's integrity.

Affected Version(s)

WCR-1166DS firmware Ver. 1.34 and earlier

WSR-1166DHP firmware Ver. 1.16 and earlier

WSR-1166DHP2 firmware Ver. 1.17 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.