OS Command Injection Vulnerability in Buffalo Network Devices
CVE-2022-43466

6.8MEDIUM

Key Information:

Vendor
CVE Published:
19 December 2022

What is CVE-2022-43466?

An OS command injection vulnerability exists in Buffalo network devices, permitting an attacker with administrative access to execute arbitrary operating system commands by sending a specially crafted request to a specific CGI program. This can lead to unauthorized access and potentially compromise the integrity and privacy of the network.

Affected Version(s)

WEX-1800AX4 firmware Ver. 1.13 and earlier

WEX-1800AX4EA firmware Ver. 1.13 and earlier

WSR-2533DHP2 firmware Ver. 1.22 and earlier

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.