Description
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
Published: 2024-09-10
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Buffalo Inc
Buffalo Inc wex 1166dhp
Buffalo Inc wex 1166dhp2
Buffalo Inc wex 1166dhps
Buffalo Inc wex 300hpsn
Buffalo Inc wex 300hptxn
Buffalo Inc wex 733dhp
Buffalo Inc wex 733dhp2
Buffalo Inc wex 733dhps
Buffalo Inc wex 733hptx
Buffalo Inc whr 1166dhp
Buffalo Inc whr 1166dhp2
Buffalo Inc whr 1166dhp3
Buffalo Inc whr 1166dhp4
Buffalo Inc whr 300hp2
Buffalo Inc whr 600d
Buffalo Inc wmr 300
Buffalo Inc wsr 1166dhp3
Buffalo Inc wsr 600dhp
Weaknesses CWE-78
CPEs cpe:2.3:h:buffalo_inc:wex_1166dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_1166dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_1166dhps:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_300hpsn:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_300hptxn:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhps:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733hptx:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp3:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp4:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_300hp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_600d:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wmr_300:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wsr_1166dhp3:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wsr_600dhp:*:*:*:*:*:*:*:*
Vendors & Products Buffalo Inc
Buffalo Inc wex 1166dhp
Buffalo Inc wex 1166dhp2
Buffalo Inc wex 1166dhps
Buffalo Inc wex 300hpsn
Buffalo Inc wex 300hptxn
Buffalo Inc wex 733dhp
Buffalo Inc wex 733dhp2
Buffalo Inc wex 733dhps
Buffalo Inc wex 733hptx
Buffalo Inc whr 1166dhp
Buffalo Inc whr 1166dhp2
Buffalo Inc whr 1166dhp3
Buffalo Inc whr 1166dhp4
Buffalo Inc whr 300hp2
Buffalo Inc whr 600d
Buffalo Inc wmr 300
Buffalo Inc wsr 1166dhp3
Buffalo Inc wsr 600dhp
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 07:15:00 +0000

Type Values Removed Values Added
Description OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
References

Subscriptions

Buffalo Inc Wex 1166dhp Wex 1166dhp2 Wex 1166dhps Wex 300hpsn Wex 300hptxn Wex 733dhp Wex 733dhp2 Wex 733dhps Wex 733hptx Whr 1166dhp Whr 1166dhp2 Whr 1166dhp3 Whr 1166dhp4 Whr 300hp2 Whr 600d Wmr 300 Wsr 1166dhp3 Wsr 600dhp
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-09-10T19:58:39.140Z

Reserved: 2024-08-19T02:08:40.600Z

Link: CVE-2024-44072

cve-icon Vulnrichment

Updated: 2024-09-10T19:02:33.417Z

cve-icon NVD

Status : Deferred

Published: 2024-09-10T07:15:01.963

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-44072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses