#VU70084 Hidden functionality in BUFFALO INC. products - CVE-2022-43486

 

#VU70084 Hidden functionality in BUFFALO INC. products - CVE-2022-43486

Published: December 9, 2022


Vulnerability identifier: #VU70084
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-43486
CWE-ID: CWE-912
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
WSR-3200AX4S
WSR-3200AX4B
WSR-2533DHP
WSR-2533DHP2
WSR-A2533DHP2
WSR-2533DHP3
WSR-A2533DHP3
WSR-2533DHPL
WSR-2533DHPL2
WSR-2533DHPLS
WCR-1166DS
WEX-1800AX4
WEX-1800AX4EA
Software vendor:
BUFFALO INC.

Description

The vulnerability allows a remote user to compromise vulnerable system

The vulnerability exists due to hidden functionality (backdoor) is present in software. A remote administrator on the local network can use this functionality to gain full access to the application and execute arbitrary commands on the system.


Remediation

Install updates from vendor's website.

External links