Hidden Functionality Vulnerability in Buffalo Network Devices
CVE-2022-43486

6.8MEDIUM

Key Information:

Vendor
CVE Published:
19 December 2022

What is CVE-2022-43486?

A hidden functionality vulnerability exists in Buffalo network devices, which may be exploited by an adjacent attacker possessing administrative privileges. This security flaw allows the attacker to enable debug functionalities and execute arbitrary commands on the affected devices, potentially leading to unauthorized access and control over network operations.

Affected Version(s)

WCR-1166DS firmware Ver. 1.34 and earlier

WEX-1800AX4 firmware Ver. 1.13 and earlier

WEX-1800AX4EA firmware Ver. 1.13 and earlier

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.