Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-01-24T04:35:55.337Z
Updated: 2024-08-01T22:43:34.585Z
Reserved: 2024-01-09T07:04:26.494Z
Link: CVE-2024-22366
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-01-24T05:15:13.823
Modified: 2024-11-21T08:56:07.920
Link: CVE-2024-22366
Redhat
No data.