CVE-2022-43466: OS Command Injection
Buffalo network devices WSR-3200AX4S firmware Ver. 1.26 and earlier, WSR-3200AX4B firmware Ver. 1.25, WSR-2533DHP2 firmware Ver. 1.22 and earlier, WSR-A2533DHP2 firmware Ver. 1.22 and earlier, WSR-2533DHP3 firmware Ver. 1.26 and earlier, WSR-A2533DHP3 firmware Ver. 1.26 and earlier, WSR-2533DHPL2 firmware Ver. 1.03 and earlier, WSR-2533DHPLS firmware Ver. 1.07 and earlier, WEX-1800AX4 firmware Ver. 1.13 and earlier, and WEX-1800AX4EA firmware Ver. 1.13 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command if a specially crafted request is sent to a specific CGI program.
Other sources
OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command if a specially crafted request is sent to a specific CGI program.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-43466?
CVE-2022-43466 is a vulnerability in Buffalo network devices WSR-3200AX4S firmware Ver. 1.26 and earlier, WSR-3200AX4B firmware Ver. 1.25, WSR-2533DHP2 firmware Ver. 1.22 and earlier, WSR-A2533DHP2 firmware Ver. 1.22 and earlier, WSR-2533DHP3 firmware Ver. 1.26 and earlier, WSR-A2533DHP3 firmware Ver. 1.26 and earlier, WSR-2533DHPL2 firmware Ver. 1.03, and WSR-2533DHPLS firmware Ver. 1.07 that allows unauthorized access to the device.
What is the severity of CVE-2022-43466?
The severity of CVE-2022-43466 is medium with a CVSS score of 6.8.
How can I check if my Buffalo network device is affected by CVE-2022-43466?
You can check if your Buffalo network device is affected by CVE-2022-43466 by referring to the vulnerability report provided by Buffalo or by contacting their support.
How do I fix the vulnerability CVE-2022-43466?
To fix the vulnerability CVE-2022-43466, you need to update your Buffalo network device to the latest firmware version provided by Buffalo.
Where can I find more information about CVE-2022-43466?
You can find more information about CVE-2022-43466 on the official JVN website (https://jvn.jp/en/vu/JVNVU97099584/index.html) and the Buffalo news page (https://www.buffalo.jp/news/detail/20221205-01.html).