First published: Mon Dec 19 2022(Updated: )
Buffalo network devices WSR-3200AX4S firmware Ver. 1.26 and earlier, WSR-3200AX4B firmware Ver. 1.25, WSR-2533DHP firmware Ver. 1.08 and earlier, WSR-2533DHP2 firmware Ver. 1.22 and earlier, WSR-A2533DHP2 firmware Ver. 1.22 and earlier, WSR-2533DHP3 firmware Ver. 1.26 and earlier, WSR-A2533DHP3 firmware Ver. 1.26 and earlier, WSR-2533DHPL firmware Ver. 1.08 and earlier, WSR-2533DHPL2 firmware Ver. 1.03 and earlier, WSR-2533DHPLS firmware Ver. 1.07 and earlier, and WCR-1166DS firmware Ver. 1.34 and earlier allows an network-adjacent attacker to execute an arbitrary OS command if a specially crafted request is sent to the management page.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Buffalo Wsr-3200ax4s Firmware | <=1.26 | |
Buffalo Wsr-3200ax4s Firmware | ||
All of | ||
Buffalo WSR-3200AX4B Firmware | =1.25 | |
Buffalo WSR-3200AX4B Firmware | ||
All of | ||
Buffalo WSR-A2533DHP2 Firmware | <=1.22 | |
Buffalo WSR-A2533DHP2 Firmware | ||
All of | ||
Buffalo WSR-A2533DHP2 Firmware | <=1.22 | |
Buffalo WSR-A2533DHP2 Firmware | ||
All of | ||
Buffalo WSR-A2533DHP3 Firmware | <=1.26 | |
Buffalo WSR-A2533DHP3 Firmware | ||
All of | ||
Buffalo Wsr-a2533dhp3 | <=1.26 | |
Buffalo WSR-A2533DHP3 Firmware | ||
All of | ||
Buffalo Wsr-2533dhpl2-bk Firmware | <=1.03 | |
Buffalo WSR-2533DHPL2-BK | ||
All of | ||
Buffalo WSR-2533DHPLS | <=1.07 | |
Buffalo WSR-2533DHPLS | ||
All of | ||
Buffalo WSR-2533DHP Firmware | <=1.08 | |
Buffalo WSR-2533DHP Firmware | ||
All of | ||
Buffalo Wsr-2533dhpls Firmware | <=1.08 | |
Buffalo Wsr-2533dhpl Firmware | ||
All of | ||
Buffalo WCR-1166DS Firmware | <=1.34 | |
Buffalo WCR-1166DS Firmware | ||
Buffalo Wsr-3200ax4s Firmware | <=1.26 | |
Buffalo Wsr-3200ax4s Firmware | ||
Buffalo WSR-3200AX4B Firmware | =1.25 | |
Buffalo WSR-3200AX4B Firmware | ||
Buffalo WSR-A2533DHP2 Firmware | <=1.22 | |
Buffalo WSR-A2533DHP2 Firmware | ||
Buffalo WSR-A2533DHP2 Firmware | <=1.22 | |
Buffalo WSR-A2533DHP2 Firmware | ||
Buffalo WSR-A2533DHP3 Firmware | <=1.26 | |
Buffalo WSR-A2533DHP3 Firmware | ||
Buffalo Wsr-a2533dhp3 | <=1.26 | |
Buffalo WSR-A2533DHP3 Firmware | ||
Buffalo Wsr-2533dhpl2-bk Firmware | <=1.03 | |
Buffalo WSR-2533DHPL2-BK | ||
Buffalo WSR-2533DHPLS | <=1.07 | |
Buffalo WSR-2533DHPLS | ||
Buffalo WSR-2533DHP Firmware | <=1.08 | |
Buffalo WSR-2533DHP Firmware | ||
Buffalo Wsr-2533dhpls Firmware | <=1.08 | |
Buffalo Wsr-2533dhpl Firmware | ||
Buffalo WCR-1166DS Firmware | <=1.34 | |
Buffalo WCR-1166DS Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43443 is high, with a severity value of 8.8.
Buffalo network devices WSR-3200AX4S firmware Ver. 1.26 and earlier, WSR-3200AX4B firmware Ver. 1.25, WSR-2533DHP firmware Ver. 1.08 and earlier, WSR-2533DHP2 firmware Ver. 1.22 and earlier, WSR-A2533DHP2 firmware Ver. 1.22 and earlier, WSR-2533DHP3 firmware Ver. 1.26 and earlier, WSR-A2533DHP3 firmware Ver. 1.26 and earlier are affected by CVE-2022-43443.
To fix CVE-2022-43443, update your Buffalo network device firmware to the latest version available.
You can find more information about CVE-2022-43443 at the following references: [JVN](https://jvn.jp/en/vu/JVNVU97099584/index.html), [Buffalo](https://www.buffalo.jp/news/detail/20221205-01.html).
The CWE category of CVE-2022-43443 is CWE-78 (Improper Neutralization of Special Elements used in an OS Command).