OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.

Project Subscriptions

Vendors Products
Buffalo Inc Subscribe
Wex 1166dhp Subscribe
Wex 1166dhp2 Subscribe
Wex 1166dhps Subscribe
Wex 300hpsn Subscribe
Wex 300hptxn Subscribe
Wex 733dhp Subscribe
Wex 733dhp2 Subscribe
Wex 733dhps Subscribe
Wex 733hptx Subscribe
Whr 1166dhp Subscribe
Whr 1166dhp2 Subscribe
Whr 1166dhp3 Subscribe
Whr 1166dhp4 Subscribe
Whr 300hp2 Subscribe
Whr 600d Subscribe
Wmr 300 Subscribe
Wsr 1166dhp3 Subscribe
Wsr 600dhp Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 10 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Buffalo Inc
Buffalo Inc wex 1166dhp
Buffalo Inc wex 1166dhp2
Buffalo Inc wex 1166dhps
Buffalo Inc wex 300hpsn
Buffalo Inc wex 300hptxn
Buffalo Inc wex 733dhp
Buffalo Inc wex 733dhp2
Buffalo Inc wex 733dhps
Buffalo Inc wex 733hptx
Buffalo Inc whr 1166dhp
Buffalo Inc whr 1166dhp2
Buffalo Inc whr 1166dhp3
Buffalo Inc whr 1166dhp4
Buffalo Inc whr 300hp2
Buffalo Inc whr 600d
Buffalo Inc wmr 300
Buffalo Inc wsr 1166dhp3
Buffalo Inc wsr 600dhp
Weaknesses CWE-78
CPEs cpe:2.3:h:buffalo_inc:wex_1166dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_1166dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_1166dhps:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_300hpsn:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_300hptxn:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733dhps:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wex_733hptx:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp3:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp4:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_1166dhp:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_300hp2:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:whr_600d:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wmr_300:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wsr_1166dhp3:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo_inc:wsr_600dhp:*:*:*:*:*:*:*:*
Vendors & Products Buffalo Inc
Buffalo Inc wex 1166dhp
Buffalo Inc wex 1166dhp2
Buffalo Inc wex 1166dhps
Buffalo Inc wex 300hpsn
Buffalo Inc wex 300hptxn
Buffalo Inc wex 733dhp
Buffalo Inc wex 733dhp2
Buffalo Inc wex 733dhps
Buffalo Inc wex 733hptx
Buffalo Inc whr 1166dhp
Buffalo Inc whr 1166dhp2
Buffalo Inc whr 1166dhp3
Buffalo Inc whr 1166dhp4
Buffalo Inc whr 300hp2
Buffalo Inc whr 600d
Buffalo Inc wmr 300
Buffalo Inc wsr 1166dhp3
Buffalo Inc wsr 600dhp
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 07:15:00 +0000

Type Values Removed Values Added
Description OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-09-10T19:58:39.140Z

Reserved: 2024-08-19T02:08:40.600Z

Link: CVE-2024-44072

cve-icon Vulnrichment

Updated: 2024-09-10T19:02:33.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T07:15:01.963

Modified: 2024-09-10T20:35:09.990

Link: CVE-2024-44072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses