Vulnerability Description
Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug functionalities and execute an arbitrary command on the affected devices.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Buffalo | Wsr-3200Ax4S Firmware | <= 1.26 |
| Buffalo | Wsr-3200Ax4S | - |
| Buffalo | Wsr-3200Ax4B Firmware | 1.25 |
| Buffalo | Wsr-3200Ax4B | - |
| Buffalo | Wsr-2533Dhp2 Firmware | <= 1.22 |
| Buffalo | Wsr-2533Dhp2 | - |
| Buffalo | Wsr-A2533Dhp2 Firmware | <= 1.22 |
| Buffalo | Wsr-A2533Dhp2 | - |
| Buffalo | Wsr-2533Dhp3 Firmware | <= 1.26 |
| Buffalo | Wsr-2533Dhp3 | - |
| Buffalo | Wsr-A2533Dhp3 Firmware | <= 1.26 |
| Buffalo | Wsr-A2533Dhp3 | - |
| Buffalo | Wsr-2533Dhpl2 Firmware | <= 1.03 |
| Buffalo | Wsr-2533Dhpl2 | - |
| Buffalo | Wsr-2533Dhpls Firmware | <= 1.07 |
| Buffalo | Wsr-2533Dhpls | - |
| Buffalo | Wex-1800Ax4 Firmware | <= 1.13 |
| Buffalo | Wex-1800Ax4 | - |
| Buffalo | Wex-1800Ax4Ea Firmware | <= 1.13 |
| Buffalo | Wex-1800Ax4Ea | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU97099584/
- https://www.buffalo.jp/news/detail/20240131-01.html
- https://jvn.jp/en/vu/JVNVU97099584/
- https://www.buffalo.jp/news/detail/20240131-01.html
FAQ
What is CVE-2022-43486?
CVE-2022-43486 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug functionalities and execute an arbitrary command o...
How severe is CVE-2022-43486?
CVE-2022-43486 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43486?
Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Wsr-3200Ax4S Firmware, Buffalo Wsr-3200Ax4S, Buffalo Wsr-3200Ax4B Firmware, Buffalo Wsr-3200Ax4B, Buffalo Wsr-2533Dhp2 Firmware.