CVE Database
/

CVE-2024-44072

Back to search

CVE-2024-44072

Published: Sep 10, 2024

Modified: Sep 10, 2024

PUBLISHED

Description

OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.

VendorProductVersions

BUFFALO INC.

WHR-1166DHP2

affected
Ver. 2.95 and earlier

BUFFALO INC.

WHR-1166DHP3

affected
Ver. 2.95 and earlier

BUFFALO INC.

WHR-1166DHP4

affected
Ver. 2.95 and earlier

BUFFALO INC.

WSR-1166DHP3

affected
Ver. 1.18 and earlier

BUFFALO INC.

WSR-600DHP

affected
Ver. 2.93 and earlier

BUFFALO INC.

WEX-300HPTX/N

affected
Ver. 1.02 and earlier

BUFFALO INC.

WEX-733DHP2

affected
Ver. 1.03 and earlier

BUFFALO INC.

WEX-1166DHP2

affected
Ver. 1.05 and earlier

BUFFALO INC.

WEX-1166DHPS

affected
Ver. 1.05 and earlier

BUFFALO INC.

WEX-300HPS/N

affected
Ver. 1.02 and earlier

BUFFALO INC.

WEX-733DHPS

affected
Ver. 1.02 and earlier

BUFFALO INC.

WEX-733DHPTX

affected
Ver. 1.03 and earlier

BUFFALO INC.

WEX-1166DHP

affected
Ver. 1.23 and earlier

BUFFALO INC.

WEX-733DHP

affected
Ver. 1.64 and earlier

BUFFALO INC.

WHR-1166DHP

affected
Ver. 2.92 and earlier

BUFFALO INC.

WHR-300HP2

affected
Ver. 2.51 and earlier

BUFFALO INC.

WHR-600D

affected
Ver. 2.91 and earlier

BUFFALO INC.

WMR-300

affected
Ver. 2.50 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now