VYPR
Medium severity6.8NVD Advisory· Published Dec 19, 2022· Updated Jun 17, 2026

CVE-2022-43466

CVE-2022-43466

Description

OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command if a specially crafted request is sent to a specific CGI program.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

24
  • cpe:2.3:o:buffalo:wex-1800ax4_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:buffalo:wex-1800ax4_firmware:*:*:*:*:*:*:*:*range: <=1.13
    • (no CPE)range: firmware Ver. 1.13 and earlier
  • cpe:2.3:o:buffalo:wex-1800ax4ea_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:buffalo:wex-1800ax4ea_firmware:*:*:*:*:*:*:*:*range: <=1.13
    • (no CPE)range: firmware Ver. 1.13 and earlier
  • cpe:2.3:o:buffalo:wsr-2533dhp2_firmware:*:*:*:*:*:*:*:*
    Range: <=1.22
  • cpe:2.3:o:buffalo:wsr-2533dhp3_firmware:*:*:*:*:*:*:*:*
    Range: <=1.26
  • cpe:2.3:o:buffalo:wsr-2533dhpl2_firmware:*:*:*:*:*:*:*:*
    Range: <=1.03
  • cpe:2.3:o:buffalo:wsr-2533dhpls_firmware:*:*:*:*:*:*:*:*
    Range: <=1.07
  • cpe:2.3:o:buffalo:wsr-3200ax4b_firmware:1.25:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:buffalo:wsr-3200ax4b_firmware:1.25:*:*:*:*:*:*:*
    • (no CPE)range: firmware Ver. 1.25
  • cpe:2.3:o:buffalo:wsr-3200ax4s_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:buffalo:wsr-3200ax4s_firmware:*:*:*:*:*:*:*:*range: <=1.26
    • (no CPE)range: firmware Ver. 1.26 and earlier
  • cpe:2.3:o:buffalo:wsr-a2533dhp2_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:buffalo:wsr-a2533dhp2_firmware:*:*:*:*:*:*:*:*range: <=1.22
    • (no CPE)range: firmware Ver. 1.22 and earlier
  • cpe:2.3:o:buffalo:wsr-a2533dhp3_firmware:*:*:*:*:*:*:*:*
    Range: <=1.26
  • Buffalotech/WSR-2533DHP3cpe-rescue3 versions
    firmware Ver. 1.22 and earlier+ 2 more
    • (no CPE)range: firmware Ver. 1.22 and earlier
    • (no CPE)range: firmware Ver. 1.26 and earlier
    • (no CPE)range: firmware Ver. 1.26 and earlier
  • Buffalotech/WSR-2533DHPL2cpe-rescue3 versions
    firmware Ver. 1.03 and earlier+ 2 more
    • (no CPE)range: firmware Ver. 1.03 and earlier
    • (no CPE)range: firmware Ver. 1.05
    • (no CPE)range: firmware Ver. 1.07 and earlier
  • BUFFALO INC./WXR-5700AX7Bv5
    Range: firmware Ver. 1.27 and earlier
  • BUFFALO INC./WXR-5700AX7Sv5
    Range: firmware Ver. 1.27 and earlier

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.