CVE-2024-44072: Buffalo Inc Wex-1166dhp
Medium severity, CVSS 5.7. EPSS: 0.6% chance of exploitation in the next 30 days.
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
Affected products
- Buffalo Inc Wex-1166dhp: up to and including 1.23
- Buffalo Inc Wex-1166dhp2: up to and including 1.05
- Buffalo Inc Wex-1166dhps: up to and including 1.05
- Buffalo Inc Wex-300hps/n: up to and including 1.02
- Buffalo Inc Wex-300hptx/n: up to and including 1.02
- Buffalo Inc Wex-733dhp: up to and including 1.64
- Buffalo Inc Wex-733dhp2: up to and including 1.03
- Buffalo Inc Wex-733dhps: up to and including 1.02
- Buffalo Inc Wex-733dhptx: up to and including 1.03
- Buffalo Inc Wex 1166dhp: up to and including 1.23
- Buffalo Inc Wex 1166dhp2: up to and including 1.05
- Buffalo Inc Wex 1166dhps: up to and including 1.05
- Buffalo Inc Wex 300hpsn: up to and including 1.02
- Buffalo Inc Wex 300hptxn: up to and including 1.02
- Buffalo Inc Wex 733dhp: up to and including 1.64
- Buffalo Inc Wex 733dhp2: up to and including 1.03
- Buffalo Inc Wex 733dhps: up to and including 1.02
- Buffalo Inc Wex 733hptx: up to and including 1.03
- Buffalo Inc Whr-1166dhp: up to and including 2.92
- Buffalo Inc Whr-1166dhp2: up to and including 2.95
- Buffalo Inc Whr-1166dhp3: up to and including 2.95
- Buffalo Inc Whr-1166dhp4: up to and including 2.95
- Buffalo Inc Whr-300hp2: up to and including 2.51
- Buffalo Inc Whr-600d: up to and including 2.91
- Buffalo Inc Whr 1166dhp: up to and including 2.92
- and 11 more
Published 2024-09-10. Last modified 2026-06-17.