CVE-2022-43486

MEDIUM

Buffalo WSR/WE/WCR Firmware - Authenticated Remote Code Execution via Debug Functionality

Title source: llm
STIX 2.1

Description

Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug functionalities and execute an arbitrary command on the affected devices.

References (2)

Core 2

Scores

CVSS v3 6.8
EPSS 0.0036
EPSS Percentile 28.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (13)
buffalo/wcr-1166ds_firmware < 1.34
buffalo/wex-1800ax4_firmware < 1.13
buffalo/wex-1800ax4ea_firmware < 1.13
buffalo/wsr-2533dhp2_firmware < 1.22
buffalo/wsr-2533dhp3_firmware < 1.26
buffalo/wsr-2533dhp_firmware < 1.08
buffalo/wsr-2533dhpl2_firmware < 1.03
buffalo/wsr-2533dhpl_firmware < 1.08
buffalo/wsr-2533dhpls_firmware < 1.07
buffalo/wsr-3200ax4b_firmware 1.25
... and 3 more
Published Dec 19, 2022
Tracked Since Feb 18, 2026