CVE-2022-39044

MEDIUMCVSS 6.8/10EPSS 0.32%

Last modified

CVE-2022-39044 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command. The affected products/versions are as follows: WCR-300 firmware Ver. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and earlier, WPL-05G300 firmware Ver. 1.88 and earlier, WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, WZR-HP-AG300H firmware Ver. 1.76 and earlier, WZR-HP-G302H firmware Ver. 1.86 and earlier, WLAE-AG300N firmware Ver. 1.86 and earlier, FS-600DHP firmware Ver. 3.40 and earlier, FS-G300N firmware Ver. 3.14 and earlier, FS-HP-G300N firmware Ver. 3.33 and earlier, FS-R600DHP firmware Ver. 3.40 and earlier, BHR-4GRV firmware Ver. 2.00 and earlier, DWR-HP-G300NH firmware Ver. 1.84 and earlier, DWR-PG firmware Ver. 1.83 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WER-A54G54 firmware Ver. 1.43 and earlier, WER-AG54 firmware Ver. 1.43 and earlier, WER-AM54G54 firmware Ver. 1.43 and earlier, WER-AMG54 firmware Ver. 1.43 and earlier, WHR-300 firmware Ver. 2.00 and earlier, WHR-300HP firmware Ver. 2.00 and earlier, WHR-AM54G54 firmware Ver. 1.43 and earlier, WHR-AMG54 firmware Ver. 1.43 and earlier, WHR-AMPG firmware Ver. 1.52 and earlier, WHR-G firmware Ver. 1.49 and earlier, WHR-G300N firmware Ver. 1.65 and earlier, WHR-G301N firmware Ver. 1.87 and earlier, WHR-G54S firmware Ver. 1.43 and earlier, WHR-G54S-NI firmware Ver. 1.24 and earlier, WHR-HP-AMPG firmware Ver. 1.43 and earlier, WHR-HP-G firmware Ver. 1.49 and earlier, WHR-HP-G54 firmware Ver. 1.43 and earlier, WLI-H4-D600 firmware Ver. 1.88 and earlier, WLI-TX4-AG300N firmware Ver. 1.53 and earlier, WS024BF firmware Ver. 1.60 and earlier, WS024BF-NW firmware Ver. 1.60 and earlier, WZR2-G108 firmware Ver. 1.33 and earlier, WZR2-G300N firmware Ver. 1.55 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, WZR-AGL300NH firmware Ver. 1.55 and earlier, WZR-AMPG144NH firmware Ver. 1.49 and earlier, WZR-AMPG300NH firmware Ver. 1.51 and earlier, WZR-D1100H firmware Ver. 2.00 and earlier, WZR-G144N firmware Ver. 1.48 and earlier, WZR-G144NH firmware Ver. 1.48 and earlier, WZR-HP-G300NH firmware Ver. 1.84 and earlier, WZR-HP-G301NH firmware Ver. 1.84 and earlier, and WZR-HP-G450H firmware Ver. 1.90 and earlier.

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.32%

23.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
BuffaloWcr-300 Firmware<= 1.87
BuffaloWhr-Hp-G300n Firmware<= 2.00
BuffaloWhr-Hp-Gn Firmware<= 1.87
BuffaloWpl-05g300 Firmware<= 1.88
BuffaloWzr-300hp Firmware<= 2.00
BuffaloWzr-450hp Firmware<= 2.00
BuffaloWzr-600dhp Firmware<= 2.00
BuffaloWzr-900dhp Firmware<= 1.15
BuffaloWzr-Hp-Ag300h Firmware<= 1.76
BuffaloWzr-Hp-G302h Firmware<= 1.86
BuffaloWlae-Ag300n Firmware<= 1.86
BuffaloFs-600dhp Firmware<= 3.40
BuffaloFs-G300n Firmware<= 3.14
BuffaloFs-Hp-G300n Firmware<= 3.33
BuffaloFs-R600dhp Firmware<= 3.40
BuffaloBhr-4grv Firmware<= 2.00
BuffaloDwr-Hp-G300nh Firmware<= 1.84
BuffaloDwr-Pg Firmware<= 1.83
BuffaloHw-450hp-Zwe Firmware<= 2.00
BuffaloWer-A54g54 Firmware<= 1.43
BuffaloWer-Ag54 Firmware<= 1.43
BuffaloWer-Am54g54 Firmware<= 1.43
BuffaloWer-Amg54 Firmware<= 1.43
BuffaloWhr-300 Firmware<= 2.00
BuffaloWhr-300hp Firmware<= 2.00
BuffaloWhr-Am54g54 Firmware<= 1.43
BuffaloWhr-Amg54 Firmware<= 1.43
BuffaloWhr-Ampg Firmware<= 1.52
BuffaloWhr-G Firmware<= 1.49
BuffaloWhr-G300n Firmware<= 1.65
BuffaloWhr-G301n Firmware<= 1.87
BuffaloWhr-G54s Firmware<= 1.43
BuffaloWhr-G54s-Ni Firmware<= 1.24
BuffaloWhr-Hp-Ampg Firmware<= 1.49
BuffaloWhr-Hp-G Firmware<= 1.49
BuffaloWhr-Hp-G54 Firmware<= 1.43
BuffaloWli-H4-D600 Firmware<= 1.88
BuffaloWli-Tx4-Ag300n Firmware<= 1.53
BuffaloWs024bf Firmware<= 1.60
BuffaloWs024bf-Nw Firmware<= 1.60
BuffaloWzr2-G108 Firmware<= 1.33
BuffaloWzr2-G300n Firmware<= 1.55
BuffaloWzr-450hp-Cwt Firmware<= 2.00
BuffaloWzr-450hp-Ub Firmware<= 2.00
BuffaloWzr-600dhp2 Firmware<= 1.15
BuffaloWzr-Agl300nh Firmware<= 1.55
BuffaloWzr-Ampg144nh Firmware<= 1.49
BuffaloWzr-Ampg300nh Firmware<= 1.51
BuffaloWzr-D1100h Firmware<= 2.00
BuffaloWzr-G144n Firmware<= 1.48

Showing 50 of 54 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-39044?
Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and earlier, WPL-05G300 firmware Ver. 1.88 and earlier, WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, WZR-HP-AG300H firmware Ver. 1.76 and earlier, WZR-HP-G302H firmware Ver. 1.86 and earlier, WLAE-AG300N firmware Ver. 1.86 and earlier, FS-600DHP firmware Ver. 3.40 and earlier, FS-G300N firmware Ver. 3.14 and earlier, FS-HP-G300N firmware Ver. 3.33 and earlier, FS-R600DHP firmware Ver. 3.40 and earlier, BHR-4GRV firmware Ver. 2.00 and earlier, DWR-HP-G300NH firmware Ver. 1.84 and earlier, DWR-PG firmware Ver. 1.83 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WER-A54G54 firmware Ver. 1.43 and earlier, WER-AG54 firmware Ver. 1.43 and earlier, WER-AM54G54 firmware Ver. 1.43 and earlier, WER-AMG54 firmware Ver. 1.43 and earlier, WHR-300 firmware Ver. 2.00 and earlier, WHR-300HP firmware Ver. 2.00 and earlier, WHR-AM54G54 firmware Ver. 1.43 and earlier, WHR-AMG54 firmware Ver. 1.43 and earlier, WHR-AMPG firmware Ver. 1.52 and earlier, WHR-G firmware Ver. 1.49 and earlier, WHR-G300N firmware Ver. 1.65 and earlier, WHR-G301N firmware Ver. 1.87 and earlier, WHR-G54S firmware Ver. 1.43 and earlier, WHR-G54S-NI firmware Ver. 1.24 and earlier, WHR-HP-AMPG firmware Ver. 1.43 and earlier, WHR-HP-G firmware Ver. 1.49 and earlier, WHR-HP-G54 firmware Ver. 1.43 and earlier, WLI-H4-D600 firmware Ver. 1.88 and earlier, WLI-TX4-AG300N firmware Ver. 1.53 and earlier, WS024BF firmware Ver. 1.60 and earlier, WS024BF-NW firmware Ver. 1.60 and earlier, WZR2-G108 firmware Ver. 1.33 and earlier, WZR2-G300N firmware Ver. 1.55 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, WZR-AGL300NH firmware Ver. 1.55 and earlier, WZR-AMPG144NH firmware Ver. 1.49 and earlier, WZR-AMPG300NH firmware Ver. 1.51 and earlier, WZR-D1100H firmware Ver. 2.00 and earlier, WZR-G144N firmware Ver. 1.48 and earlier, WZR-G144NH firmware Ver. 1.48 and earlier, WZR-HP-G300NH firmware Ver. 1.84 and earlier, WZR-HP-G301NH firmware Ver. 1.84 and earlier, and WZR-HP-G450H firmware Ver. 1.90 and earlier.
How severe is CVE-2022-39044?
CVE-2022-39044 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2022-39044?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-39044?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST