CVE-2024-22366: Yamaha WLX202 Firmware
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.
Affected products
- Yamaha WLX202 Firmware: before 16.00.19 (fixed in 16.00.19)
- Yamaha WLX212 Firmware: before 21.00.13 (fixed in 21.00.13)
- Yamaha WLX222 Firmware: before 24.00.04 (fixed in 24.00.04)
- Yamaha WLX313 Firmware: before 18.00.13 (fixed in 18.00.13)
- Yamaha WLX413 Firmware: before 22.00.06 (fixed in 22.00.06)
Published 2024-01-24. Last modified 2026-06-17.