CVE-2022-43443

OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially crafted request is sent to the management page.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:buffalo:wsr-3200ax4s:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wsr-3200ax4s_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:buffalo:wsr-3200ax4b:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wsr-3200ax4b_firmware:1.25:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:buffalo:wsr-2533dhp2:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wsr-2533dhp2_firmware:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:buffalo:wsr-a2533dhp2:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wsr-a2533dhp2_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:buffalo:wsr-2533dhp3:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wsr-2533dhp3_firmware:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:buffalo:wsr-a2533dhp3:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wsr-a2533dhp3_firmware:*:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:buffalo:wsr-2533dhpl2:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wsr-2533dhpl2_firmware:*:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:buffalo:wsr-2533dhpls_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-2533dhpls:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:buffalo:wsr-2533dhp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-2533dhp:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:buffalo:wsr-2533dhpl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-2533dhpl:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:buffalo:wcr-1166ds_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wcr-1166ds:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-12-19 03:15

Updated : 2024-02-14 07:15


NVD link : CVE-2022-43443

Mitre link : CVE-2022-43443

CVE.ORG link : CVE-2022-43443


JSON object : View

Products Affected

buffalo

  • wsr-2533dhp3_firmware
  • wsr-2533dhpls_firmware
  • wsr-a2533dhp3_firmware
  • wsr-3200ax4b_firmware
  • wsr-2533dhp2_firmware
  • wsr-a2533dhp2
  • wsr-2533dhp
  • wsr-3200ax4b
  • wsr-2533dhpl2_firmware
  • wcr-1166ds
  • wsr-2533dhpls
  • wsr-3200ax4s_firmware
  • wsr-2533dhp2
  • wsr-2533dhpl2
  • wsr-a2533dhp3
  • wsr-3200ax4s
  • wsr-2533dhpl_firmware
  • wsr-2533dhp_firmware
  • wsr-2533dhpl
  • wcr-1166ds_firmware
  • wsr-2533dhp3
  • wsr-a2533dhp2_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')