PT-2022-24693 · Buffalo · Wli-H4-D600+48

Chuya Hayakawa

·

Published

2022-12-07

·

Updated

2022-12-13

·

CVE-2022-39044

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WCR-300 firmware Ver. 1.87 and earlier WHR-HP-G300N firmware Ver. 2.00 and earlier WHR-HP-GN firmware Ver. 1.87 and earlier WPL-05G300 firmware Ver. 1.88 and earlier WZR-300HP firmware Ver. 2.00 and earlier WZR-450HP firmware Ver. 2.00 and earlier WZR-600DHP firmware Ver. 2.00 and earlier WZR-900DHP firmware Ver. 1.15 and earlier WZR-HP-AG300H firmware Ver. 1.76 and earlier WZR-HP-G302H firmware Ver. 1.86 and earlier WLAE-AG300N firmware Ver. 1.86 and earlier FS-600DHP firmware Ver. 3.40 and earlier FS-G300N firmware Ver. 3.14 and earlier FS-HP-G300N firmware Ver. 3.33 and earlier FS-R600DHP firmware Ver. 3.40 and earlier BHR-4GRV firmware Ver. 2.00 and earlier DWR-HP-G300NH firmware Ver. 1.84 and earlier DWR-PG firmware Ver. 1.83 and earlier HW-450HP-ZWE firmware Ver. 2.00 and earlier WER-A54G54 firmware Ver. 1.43 and earlier WER-AG54 firmware Ver. 1.43 and earlier WER-AM54G54 firmware Ver. 1.43 and earlier WER-AMG54 firmware Ver. 1.43 and earlier WHR-300 firmware Ver. 2.00 and earlier WHR-300HP firmware Ver. 2.00 and earlier WHR-AM54G54 firmware Ver. 1.43 and earlier WHR-AMG54 firmware Ver. 1.43 and earlier WHR-AMPG firmware Ver. 1.52 and earlier WHR-G firmware Ver. 1.49 and earlier WHR-G300N firmware Ver. 1.65 and earlier WHR-G301N firmware Ver. 1.87 and earlier WHR-G54S firmware Ver. 1.43 and earlier WHR-G54S-NI firmware Ver. 1.24 and earlier WHR-HP-AMPG firmware Ver. 1.43 and earlier WHR-HP-G firmware Ver. 1.49 and earlier WHR-HP-G54 firmware Ver. 1.43 and earlier WLI-H4-D600 firmware Ver. 1.88 and earlier WLI-TX4-AG300N firmware Ver. 1.53 and earlier WS024BF firmware Ver. 1.60 and earlier WS024BF-NW firmware Ver. 1.60 and earlier WZR2-G108 firmware Ver. 1.33 and earlier WZR2-G300N firmware Ver. 1.55 and earlier WZR-450HP-CWT firmware Ver. 2.00 and earlier WZR-450HP-UB firmware Ver. 2.00 and earlier WZR-600DHP2 firmware Ver. 1.15 and earlier WZR-AGL300NH firmware Ver. 1.55 and earlier WZR-AMPG144NH firmware Ver. 1.49 and earlier WZR-AMPG300NH firmware Ver. 1.51 and earlier WZR-D1100H firmware Ver. 2.00 and earlier WZR-G144N firmware Ver. 1.48 and earlier WZR-G144NH firmware Ver. 1.48 and earlier WZR-HP-G300NH firmware Ver. 1.84 and earlier WZR-HP-G301NH firmware Ver. 1.84 and earlier WZR-HP-G450H firmware Ver. 1.90 and earlier
Description A hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with administrative privilege to execute an arbitrary OS command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2022-39044

Affected Products

Bhr-4Grv
Dwr-Hp-G300Nh
Dwr-Pg
Fs-600Dhp
Fs-G300N
Fs-Hp-G300N
Fs-R600Dhp
Hw-450Hp-Zwe
Wcr-300
Wer-Am54G54
Wer-Amg54
Whr-300
Whr-300Hp
Whr-Am54G54
Whr-Amg54
Whr-Ampg
Whr-G
Whr-G300N
Whr-G301N
Whr-G54S
Whr-G54S-Ni
Whr-Hp-Ampg
Whr-Hp-Gn
Whr-Hp-G300N
Whr-Hp-G54
Wlae-Ag300N
Wli-H4-D600
Wli-Tx4-Ag300N
Wpl-05G300
Ws024Bf
Ws024Bf-Nw
Wzr-300Hp
Wzr-450Hp
Wzr-450Hp-Cwt
Wzr-450Hp-Ub
Wzr-600Dhp
Wzr-600Dhp2
Wzr-900Dhp
Wzr-Agl300Nh
Wzr-Ampg144Nh
Wzr-Ampg300Nh
Wzr-D1100H
Wzr-G144N
Wzr-Hp-Ag300H
Wzr-Hp-G301Nh
Wzr-Hp-G302H
Wzr-Hp-G450H
Wzr2-G108
Wzr2-G300N