CVE-2024-22366

MEDIUM

Yamaha Wireless LAN Access Point - RCE

Title source: llm
STIX 2.1

Description

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.

References (2)

Core 2

Scores

CVSS v3 6.8
EPSS 0.0032
EPSS Percentile 23.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (5)
yamaha/wlx202_firmware < 16.00.19
yamaha/wlx212_firmware < 21.00.13
yamaha/wlx222_firmware < 24.00.04
yamaha/wlx313_firmware < 18.00.13
yamaha/wlx413_firmware < 22.00.06
Published Jan 24, 2024
Tracked Since Feb 18, 2026