CVE-2014-9284

The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, and BHR-4GRV2 1.04 and earlier routers allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:buffalotech:wsr-600dhp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalotech:wsr-600dhp:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:buffalotech:whr-300hp2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalotech:whr-300hp2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:buffalotech:whr-1166dhp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalotech:whr-1166dhp:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:buffalotech:bhr-4grv2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalotech:bhr-4grv2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:buffalotech:wmr-300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalotech:wmr-300:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:buffalotech:wex-300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalotech:wex-300:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:buffalotech:whr-600d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalotech:whr-600d:-:*:*:*:*:*:*:*

Information

Published : 2015-06-08 17:59

Updated : 2015-06-16 08:59


NVD link : CVE-2014-9284

Mitre link : CVE-2014-9284


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

buffalotech

  • wmr-300
  • wex-300_firmware
  • wsr-600dhp
  • whr-600d
  • bhr-4grv2
  • wsr-600dhp_firmware
  • whr-600d_firmware
  • whr-300hp2_firmware
  • wex-300
  • whr-300hp2
  • whr-1166dhp_firmware
  • wmr-300_firmware
  • whr-1166dhp
  • bhr-4grv2_firmware