Vulnerability Description
OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Buffalo | Wsr-2533Dhp Firmware | < 1.07 |
| Buffalo | Wsr-2533Dhp | - |
| Buffalo | Wsr-2533Dhpl Firmware | < 1.07 |
| Buffalo | Wsr-2533Dhpl | - |
| Buffalo | Wsr-2533Dhp2 Firmware | < 1.11 |
| Buffalo | Wsr-2533Dhp2 | - |
| Buffalo | Wsr-A2533Dhp2 Firmware | < 1.11 |
| Buffalo | Wsr-A2533Dhp2 | - |
| Buffalo | Wcr-1166Ds Firmware | < 1.33 |
| Buffalo | Wcr-1166Ds | - |
| Buffalo | Wsr-1166Dhp Firmware | < 1.15 |
| Buffalo | Wsr-1166Dhp | - |
| Buffalo | Wsr-1166Dhp2 Firmware | < 1.15 |
| Buffalo | Wsr-1166Dhp2 | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN58236836/Third Party Advisory
- https://www.buffalo.jp/news/detail/20240410-01.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN58236836/Third Party Advisory
- https://www.buffalo.jp/news/detail/20240410-01.htmlVendor Advisory
FAQ
What is CVE-2024-26023?
CVE-2024-26023 is a vulnerability with a CVSS score of 4.2 (MEDIUM). OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.
How severe is CVE-2024-26023?
CVE-2024-26023 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26023?
Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Wsr-2533Dhp Firmware, Buffalo Wsr-2533Dhp, Buffalo Wsr-2533Dhpl Firmware, Buffalo Wsr-2533Dhpl, Buffalo Wsr-2533Dhp2 Firmware.