Vulnerability Description
OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially crafted request is sent to the management page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Buffalo | Wsr-3200Ax4S Firmware | <= 1.26 |
| Buffalo | Wsr-3200Ax4S | - |
| Buffalo | Wsr-3200Ax4B Firmware | 1.25 |
| Buffalo | Wsr-3200Ax4B | - |
| Buffalo | Wsr-2533Dhp2 Firmware | <= 1.22 |
| Buffalo | Wsr-2533Dhp2 | - |
| Buffalo | Wsr-A2533Dhp2 Firmware | <= 1.22 |
| Buffalo | Wsr-A2533Dhp2 | - |
| Buffalo | Wsr-2533Dhp3 Firmware | <= 1.26 |
| Buffalo | Wsr-2533Dhp3 | - |
| Buffalo | Wsr-A2533Dhp3 Firmware | <= 1.26 |
| Buffalo | Wsr-A2533Dhp3 | - |
| Buffalo | Wsr-2533Dhpl2 Firmware | <= 1.03 |
| Buffalo | Wsr-2533Dhpl2 | - |
| Buffalo | Wsr-2533Dhpls Firmware | <= 1.07 |
| Buffalo | Wsr-2533Dhpls | - |
| Buffalo | Wsr-2533Dhp Firmware | <= 1.08 |
| Buffalo | Wsr-2533Dhp | - |
| Buffalo | Wsr-2533Dhpl Firmware | <= 1.08 |
| Buffalo | Wsr-2533Dhpl | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU97099584/
- https://www.buffalo.jp/news/detail/20240131-01.html
- https://jvn.jp/en/vu/JVNVU97099584/
- https://www.buffalo.jp/news/detail/20240131-01.html
FAQ
What is CVE-2022-43443?
CVE-2022-43443 is a vulnerability with a CVSS score of 8.8 (HIGH). OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially crafted request is sent to the management page.
How severe is CVE-2022-43443?
CVE-2022-43443 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43443?
Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Wsr-3200Ax4S Firmware, Buffalo Wsr-3200Ax4S, Buffalo Wsr-3200Ax4B Firmware, Buffalo Wsr-3200Ax4B, Buffalo Wsr-2533Dhp2 Firmware.