Security Advisory

CVE-2024-22366

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-01-24 04:35:55
Last updated 2025-06-20 19:27:11
Assigner jpcert
CVSS score not scored
State PUBLISHED

Description

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.