CVE-2022-43466
published 2022-12-19CVE-2022-43466: OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS…
PriorityP339medium6.8CVSS 3.1
AVAACLPRHUINSUCHIHAH
EPSS
0.78%
51.2th percentile
OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command if a specially crafted request is sent to a specific CGI program.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| buffalo | wex-1800ax4_firmware | <= 1.13 | — |
| buffalo | wex-1800ax4ea_firmware | <= 1.13 | — |
| buffalo | wsr-2533dhp2_firmware | <= 1.22 | — |
| buffalo | wsr-2533dhp3_firmware | <= 1.26 | — |
| buffalo | wsr-2533dhpl2_firmware | <= 1.03 | — |
| buffalo | wsr-2533dhpls_firmware | <= 1.07 | — |
| buffalo | wsr-3200ax4b_firmware | — | — |
| buffalo | wsr-3200ax4s_firmware | <= 1.26 | — |
| buffalo | wsr-a2533dhp2_firmware | <= 1.22 | — |
| buffalo | wsr-a2533dhp3_firmware | <= 1.26 | — |
| buffalo_inc | wex-1800ax4 | — | — |
| buffalo_inc | wex-1800ax4ea | — | — |
| buffalo_inc | wsr-2533dhp2 | — | — |
| buffalo_inc | wsr-2533dhp3 | — | — |
| buffalo_inc | wsr-2533dhpl2 | — | — |
| buffalo_inc | wsr-2533dhplb | — | — |
| buffalo_inc | wsr-2533dhpls | — | — |
| buffalo_inc | wsr-3200ax4b | — | — |
| buffalo_inc | wsr-3200ax4s | — | — |
| buffalo_inc | wsr-a2533dhp2 | — | — |
| buffalo_inc | wsr-a2533dhp3 | — | — |
| buffalo_inc | wxr-5700ax7b | — | — |
| buffalo_inc | wxr-5700ax7s | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-19
Published