OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
History

Tue, 10 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Buffalo Inc
Buffalo Inc wex 1166dhp
Buffalo Inc wex 1166dhp2
Buffalo Inc wex 1166dhps
Buffalo Inc wex 300hpsn
Buffalo Inc wex 300hptxn
Buffalo Inc wex 733dhp
Buffalo Inc wex 733dhp2
Buffalo Inc wex 733dhps
Buffalo Inc wex 733hptx
Buffalo Inc whr 1166dhp
Buffalo Inc whr 1166dhp2
Buffalo Inc whr 1166dhp3
Buffalo Inc whr 1166dhp4
Buffalo Inc whr 300hp2
Buffalo Inc whr 600d
Buffalo Inc wmr 300
Buffalo Inc wsr 1166dhp3
Buffalo Inc wsr 600dhp
Weaknesses CWE-78
CPEs cpe:2.3:h:buffalo_inc:wex_1166dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_1166dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_1166dhps:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_300hpsn:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_300hptxn:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhps:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733hptx:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp3:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp4:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_300hp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_600d:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wmr_300:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wsr_1166dhp3:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wsr_600dhp:*:*:*:*:*:*:*:*
Vendors & Products Buffalo Inc
Buffalo Inc wex 1166dhp
Buffalo Inc wex 1166dhp2
Buffalo Inc wex 1166dhps
Buffalo Inc wex 300hpsn
Buffalo Inc wex 300hptxn
Buffalo Inc wex 733dhp
Buffalo Inc wex 733dhp2
Buffalo Inc wex 733dhps
Buffalo Inc wex 733hptx
Buffalo Inc whr 1166dhp
Buffalo Inc whr 1166dhp2
Buffalo Inc whr 1166dhp3
Buffalo Inc whr 1166dhp4
Buffalo Inc whr 300hp2
Buffalo Inc whr 600d
Buffalo Inc wmr 300
Buffalo Inc wsr 1166dhp3
Buffalo Inc wsr 600dhp
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 07:15:00 +0000

Type Values Removed Values Added
Description OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-09-10T06:56:44.182Z

Updated: 2024-09-10T19:58:39.140Z

Reserved: 2024-08-19T02:08:40.600Z

Link: CVE-2024-44072

cve-icon Vulnrichment

Updated: 2024-09-10T19:02:33.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T07:15:01.963

Modified: 2024-09-10T20:35:09.990

Link: CVE-2024-44072

cve-icon Redhat

No data.