Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22366

Опубликовано: 24 янв. 2024
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:yamaha:wlx222_firmware:*:*:*:*:*:*:*:*
Версия до 24.00.04 (исключая)
cpe:2.3:h:yamaha:wlx222:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:yamaha:wlx413_firmware:*:*:*:*:*:*:*:*
Версия до 22.00.06 (исключая)
cpe:2.3:h:yamaha:wlx413:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:yamaha:wlx212_firmware:*:*:*:*:*:*:*:*
Версия до 21.00.13 (исключая)
cpe:2.3:h:yamaha:wlx212:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:yamaha:wlx313_firmware:*:*:*:*:*:*:*:*
Версия до 18.00.13 (исключая)
cpe:2.3:h:yamaha:wlx313:-:*:*:*:*:*:*:*
Конфигурация 5

Одновременно

cpe:2.3:o:yamaha:wlx202_firmware:*:*:*:*:*:*:*:*
Версия до 16.00.19 (исключая)
cpe:2.3:h:yamaha:wlx202:-:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00083
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 6.8
github
около 2 лет назад

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.

EPSS

Процентиль: 24%
0.00083
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-78
CWE-78