CVE-2024-26023

OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:buffalo:wsr-2533dhp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-2533dhp:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:buffalo:wsr-2533dhpl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-2533dhpl:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:buffalo:wsr-2533dhp2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-2533dhp2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:buffalo:wsr-a2533dhp2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-a2533dhp2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:buffalo:wcr-1166ds_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wcr-1166ds:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:buffalo:wsr-1166dhp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-1166dhp:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:buffalo:wsr-1166dhp2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wsr-1166dhp2:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-04-15 11:15

Updated : 2025-06-30 13:12


NVD link : CVE-2024-26023

Mitre link : CVE-2024-26023

CVE.ORG link : CVE-2024-26023


JSON object : View

Products Affected

buffalo

  • wsr-1166dhp2
  • wsr-2533dhp2_firmware
  • wsr-2533dhpl
  • wsr-2533dhp2
  • wsr-2533dhp_firmware
  • wsr-2533dhpl_firmware
  • wsr-1166dhp
  • wsr-a2533dhp2_firmware
  • wcr-1166ds_firmware
  • wsr-1166dhp_firmware
  • wsr-1166dhp2_firmware
  • wsr-2533dhp
  • wsr-a2533dhp2
  • wcr-1166ds
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')