Remote Command Injection leakage (CVE-2014-9284) for multiple Buffalo Routers)
Remote Command Injection leakage (CVE-2014-9284) for multiple Buffalo Routers)
Release date:
Updated on:
Affected Systems:
Buffalo Technology Routers WSR-600DHP
Buffalo Technology Routers WMR-300
Buffalo Technology Routers WHR-600D
Buffalo Technology Routers WHR-300HP2
Buffalo Technology Routers WHR-1166DHP
Buffalo Technology Routers WEX-300
Buffalo Technology Routers BHR-4GRV2
Description:
Bugtraq id: 75062
CVE (CAN) ID: CVE-2014-9284
Buffalo is a provider of computer peripherals in Japan.
Buffalo WHR-1166DHP 1.60 and earlier versions, WSR-600DHP 1.60 and earlier versions, WHR-600D 1.60 and earlier versions, WHR-300HP2 1.60 and earlier versions, WMR-300 1.60 and earlier versions, WEX-300 1.60 and earlier versions, BHR-4GRV2 1.04 has a remote command injection vulnerability that authenticated remote activation exploits to execute arbitrary OS commands.
<* Source: Masashi Sakai
*>
Suggestion:
Vendor patch:
Buffalo Technology
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://jvn.jp/en/jp/JVN50447904/index.html
Http://jvndb.jvn.jp/jvndb/JVNDB-2015-000085
This article permanently updates the link address: